UBUNTU-CVE-2018-7757
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-7757
UBUNTU-CVE-2018-7757
Summary:
Details: Memory leak in the sas_smp_get_phy_events function in drivers/scsi/libsas/sas_expander.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (memory consumption) via many read accesses to files in the /sys/class/sas_phy directory, as demonstrated by the /sys/class/sas_phy/phy-1:0:12/invalid_dword_count file.
References: https://ubuntu.com/security/CVE-2018-7757, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4a491b1ab11ca0556d2fda1ff1301e862a2d44c4, https://ubuntu.com/security/notices/USN-3654-1, https://ubuntu.com/security/notices/USN-3654-2, https://ubuntu.com/security/notices/USN-3656-1, https://ubuntu.com/security/notices/USN-3697-1, https://ubuntu.com/security/notices/USN-3697-2, https://ubuntu.com/security/notices/USN-3698-1, https://ubuntu.com/security/notices/USN-3698-2, https://www.cve.org/CVERecord?id=CVE-2018-7757
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
