Kernel Vulnerability in Linux Kernel Affecting Multiple Versions
CVE-2018-5803

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
12 June 2018

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2018-5803?

The vulnerability identified in the Linux Kernel prior to version 4.15.8 involves a flaw within the '_sctp_make_chunk()' function. This flaw is triggered during the processing of SCTP packets, particularly linked to length handling, which can lead to unexpected behavior. Exploiting this flaw can result in a kernel crash, thereby impacting system stability and security. It's crucial for users and administrators to apply the necessary patches to safeguard their systems from potential exploitation.

Affected Version(s)

Linux Kernel Before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.