CVE-2018-8822: Buffer Overflow
Incorrect buffer length handling in the ncpreadkernel function in fs/ncpfs/ncplibkernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplibkernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is CVE-2018-8822?
CVE-2018-8822 is a vulnerability in the Linux kernel that allows malicious NCPFS servers to crash the kernel or execute code.
Which versions of Linux kernel are affected by CVE-2018-8822?
CVE-2018-8822 affects Linux kernel versions up to 4.15.11 and versions 4.16-rc through 4.16-rc6.
How can CVE-2018-8822 be exploited?
CVE-2018-8822 can be exploited by malicious NCPFS servers to crash the kernel or execute code.
What is the severity of CVE-2018-8822?
The severity of CVE-2018-8822 is not specified.
How can I fix CVE-2018-8822?
To fix CVE-2018-8822, update your Linux kernel to version 4.16 or later.