UBUNTU-CVE-2018-10938
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-10938
UBUNTU-CVE-2018-10938
Summary:
Details: A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
References: https://ubuntu.com/security/CVE-2018-10938, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=40413955ee265a5e42f710940ec78f5450d49149, http://www.openwall.com/lists/oss-security/2018/08/27/1, http://seclists.org/oss-sec/2018/q3/179, https://marc.info/?t=153719718600001&r=1&w=2, https://marc.info/?t=153720664100001&r=1&w=2, https://ubuntu.com/security/notices/USN-3797-1, https://ubuntu.com/security/notices/USN-3797-2, https://www.cve.org/CVERecord?id=CVE-2018-10938
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
