UBUNTU-CVE-2018-10938

    Dashboard / Vulnerabilities / UBUNTU-CVE-2018-10938

    UBUNTU-CVE-2018-10938

    Published: 27 Aug 2018Last Modified: 22 Apr 2026

    Summary:

    Details: A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.

    Affected packages

    Package

    Name: linux-aws

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.4.0-1032.35

    Affected versions

    4.4.0-1002.2
    4.4.0-1003.3
    4.4.0-1005.5
    4.4.0-1006.6
    4.4.0-1009.9
    4.4.0-1010.10
    4.4.0-1011.11
    4.4.0-1012.12
    4.4.0-1014.14
    4.4.0-1016.16
    4.4.0-1017.17
    4.4.0-1019.19
    4.4.0-1022.22
    4.4.0-1023.23
    4.4.0-1024.25
    4.4.0-1025.26
    4.4.0-1027.30
    4.4.0-1028.31
    4.4.0-1029.32
    4.4.0-1031.34

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High