UBUNTU-CVE-2018-5332
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-5332
UBUNTU-CVE-2018-5332
Summary:
Details: In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
References: https://ubuntu.com/security/CVE-2018-5332, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c095508770aebf1b9218e77026e48345d719b17c, https://github.com/torvalds/linux/commit/c095508770aebf1b9218e77026e48345d719b17c, https://ubuntu.com/security/notices/USN-3617-1, https://ubuntu.com/security/notices/USN-3617-2, https://ubuntu.com/security/notices/USN-3617-3, https://ubuntu.com/security/notices/USN-3619-1, https://ubuntu.com/security/notices/USN-3620-1, https://ubuntu.com/security/notices/USN-3620-2, https://ubuntu.com/security/notices/USN-3619-2, https://ubuntu.com/security/notices/USN-3632-1, https://www.cve.org/CVERecord?id=CVE-2018-5332
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
