7.1
CVSSv2

CVE-2018-10938

Published: 27/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 4.0

linux linux kernel 4.1

linux linux kernel 4.2

linux linux kernel 4.4

linux linux kernel 4.6

linux linux kernel 4.8

linux linux kernel 4.10

linux linux kernel 4.12

linux linux kernel 4.3

linux linux kernel 4.5

linux linux kernel 4.7

linux linux kernel 4.9

linux linux kernel 4.11

linux linux kernel 4.13

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2018-6554 A memory leak in the irda_bind function in the irda subsystem was discovered A local user can take advantage of this flaw to cause a denial of service (memory consumption) CVE ...
A flaw was found in the Linux kernel present since v40-rc1 and through v413-rc4 A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4c leading to a denial-of-service A certain non-default configuration of LSM (Linux Security Module) and NetL ...