7.1

CVE-2018-10938

A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version 4.0
Linux ≫ Linux Kernel Version 4.0 Update rc1
Linux ≫ Linux Kernel Version 4.0 Update rc2
Linux ≫ Linux Kernel Version 4.0 Update rc3
Linux ≫ Linux Kernel Version 4.0 Update rc4
Linux ≫ Linux Kernel Version 4.0 Update rc5
Linux ≫ Linux Kernel Version 4.0 Update rc6
Linux ≫ Linux Kernel Version 4.0 Update rc7
Linux ≫ Linux Kernel Version 4.1
Linux ≫ Linux Kernel Version 4.1 Update rc1
Linux ≫ Linux Kernel Version 4.1 Update rc2
Linux ≫ Linux Kernel Version 4.1 Update rc3
Linux ≫ Linux Kernel Version 4.1 Update rc4
Linux ≫ Linux Kernel Version 4.1 Update rc5
Linux ≫ Linux Kernel Version 4.1 Update rc6
Linux ≫ Linux Kernel Version 4.1 Update rc7
Linux ≫ Linux Kernel Version 4.1 Update rc8
Linux ≫ Linux Kernel Version 4.2
Linux ≫ Linux Kernel Version 4.2 Update rc1
Linux ≫ Linux Kernel Version 4.2 Update rc2
Linux ≫ Linux Kernel Version 4.2 Update rc3
Linux ≫ Linux Kernel Version 4.2 Update rc4
Linux ≫ Linux Kernel Version 4.2 Update rc5
Linux ≫ Linux Kernel Version 4.2 Update rc6
Linux ≫ Linux Kernel Version 4.2 Update rc7
Linux ≫ Linux Kernel Version 4.2 Update rc8
Linux ≫ Linux Kernel Version 4.3
Linux ≫ Linux Kernel Version 4.3 Update rc1
Linux ≫ Linux Kernel Version 4.3 Update rc2
Linux ≫ Linux Kernel Version 4.3 Update rc3
Linux ≫ Linux Kernel Version 4.3 Update rc4
Linux ≫ Linux Kernel Version 4.3 Update rc5
Linux ≫ Linux Kernel Version 4.3 Update rc6
Linux ≫ Linux Kernel Version 4.3 Update rc7
Linux ≫ Linux Kernel Version 4.4
Linux ≫ Linux Kernel Version 4.4 Update rc1
Linux ≫ Linux Kernel Version 4.4 Update rc2
Linux ≫ Linux Kernel Version 4.4 Update rc3
Linux ≫ Linux Kernel Version 4.4 Update rc4
Linux ≫ Linux Kernel Version 4.4 Update rc5
Linux ≫ Linux Kernel Version 4.4 Update rc6
Linux ≫ Linux Kernel Version 4.4 Update rc7
Linux ≫ Linux Kernel Version 4.4 Update rc8
Linux ≫ Linux Kernel Version 4.5
Linux ≫ Linux Kernel Version 4.5 Update rc1
Linux ≫ Linux Kernel Version 4.5 Update rc2
Linux ≫ Linux Kernel Version 4.5 Update rc3
Linux ≫ Linux Kernel Version 4.5 Update rc4
Linux ≫ Linux Kernel Version 4.5 Update rc5
Linux ≫ Linux Kernel Version 4.5 Update rc6
Linux ≫ Linux Kernel Version 4.5 Update rc7
Linux ≫ Linux Kernel Version 4.6
Linux ≫ Linux Kernel Version 4.6 Update rc1
Linux ≫ Linux Kernel Version 4.6 Update rc2
Linux ≫ Linux Kernel Version 4.6 Update rc3
Linux ≫ Linux Kernel Version 4.6 Update rc4
Linux ≫ Linux Kernel Version 4.6 Update rc5
Linux ≫ Linux Kernel Version 4.6 Update rc6
Linux ≫ Linux Kernel Version 4.6 Update rc7
Linux ≫ Linux Kernel Version 4.7
Linux ≫ Linux Kernel Version 4.7 Update rc1
Linux ≫ Linux Kernel Version 4.7 Update rc2
Linux ≫ Linux Kernel Version 4.7 Update rc3
Linux ≫ Linux Kernel Version 4.7 Update rc4
Linux ≫ Linux Kernel Version 4.7 Update rc5
Linux ≫ Linux Kernel Version 4.7 Update rc6
Linux ≫ Linux Kernel Version 4.7 Update rc7
Linux ≫ Linux Kernel Version 4.8
Linux ≫ Linux Kernel Version 4.8 Update rc1
Linux ≫ Linux Kernel Version 4.8 Update rc2
Linux ≫ Linux Kernel Version 4.8 Update rc3
Linux ≫ Linux Kernel Version 4.8 Update rc4
Linux ≫ Linux Kernel Version 4.8 Update rc5
Linux ≫ Linux Kernel Version 4.8 Update rc6
Linux ≫ Linux Kernel Version 4.8 Update rc7
Linux ≫ Linux Kernel Version 4.8 Update rc8
Linux ≫ Linux Kernel Version 4.9
Linux ≫ Linux Kernel Version 4.9 Update rc1
Linux ≫ Linux Kernel Version 4.9 Update rc2
Linux ≫ Linux Kernel Version 4.9 Update rc3
Linux ≫ Linux Kernel Version 4.9 Update rc4
Linux ≫ Linux Kernel Version 4.9 Update rc5
Linux ≫ Linux Kernel Version 4.9 Update rc6
Linux ≫ Linux Kernel Version 4.9 Update rc7
Linux ≫ Linux Kernel Version 4.9 Update rc8
Linux ≫ Linux Kernel Version 4.10
Linux ≫ Linux Kernel Version 4.10 Update rc1
Linux ≫ Linux Kernel Version 4.10 Update rc2
Linux ≫ Linux Kernel Version 4.10 Update rc3
Linux ≫ Linux Kernel Version 4.10 Update rc4
Linux ≫ Linux Kernel Version 4.10 Update rc5
Linux ≫ Linux Kernel Version 4.10 Update rc6
Linux ≫ Linux Kernel Version 4.10 Update rc7
Linux ≫ Linux Kernel Version 4.10 Update rc8
Linux ≫ Linux Kernel Version 4.11
Linux ≫ Linux Kernel Version 4.11 Update rc1
Linux ≫ Linux Kernel Version 4.11 Update rc2
Linux ≫ Linux Kernel Version 4.11 Update rc3
Linux ≫ Linux Kernel Version 4.11 Update rc4
Linux ≫ Linux Kernel Version 4.11 Update rc5
Linux ≫ Linux Kernel Version 4.11 Update rc6
Linux ≫ Linux Kernel Version 4.11 Update rc7
Linux ≫ Linux Kernel Version 4.11 Update rc8
Linux ≫ Linux Kernel Version 4.12
Linux ≫ Linux Kernel Version 4.12 Update rc1
Linux ≫ Linux Kernel Version 4.12 Update rc2
Linux ≫ Linux Kernel Version 4.12 Update rc3
Linux ≫ Linux Kernel Version 4.12 Update rc4
Linux ≫ Linux Kernel Version 4.12 Update rc5
Linux ≫ Linux Kernel Version 4.12 Update rc6
Linux ≫ Linux Kernel Version 4.12 Update rc7
Linux ≫ Linux Kernel Version 4.13 Update rc1
Linux ≫ Linux Kernel Version 4.13 Update rc2
Linux ≫ Linux Kernel Version 4.13 Update rc3
Linux ≫ Linux Kernel Version 4.13 Update rc4
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Debian ≫ Debian Linux Version 9.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5% 0.911
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2018/dsa-4308
Third Party Advisory
https://usn.ubuntu.com/3797-1/
Third Party Advisory
https://usn.ubuntu.com/3797-2/
Third Party Advisory
http://seclists.org/oss-sec/2018/q3/179
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/105154
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041569
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10938
Third Party Advisory
Issue Tracking
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=40413955ee265a5e42f710940ec78f5450d49149
Third Party Advisory
Mailing List