5.5

CVE-2018-1130

Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 4.16
LinuxLinux Kernel Version4.16 Updaterc1
LinuxLinux Kernel Version4.16 Updaterc2
LinuxLinux Kernel Version4.16 Updaterc3
LinuxLinux Kernel Version4.16 Updaterc4
LinuxLinux Kernel Version4.16 Updaterc5
LinuxLinux Kernel Version4.16 Updaterc6
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.087
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
secalert@redhat.com 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://usn.ubuntu.com/3698-1/
Third Party Advisory
https://usn.ubuntu.com/3698-2/
Third Party Advisory
https://usn.ubuntu.com/3654-1/
Third Party Advisory
https://usn.ubuntu.com/3654-2/
Third Party Advisory
https://usn.ubuntu.com/3656-1/
Third Party Advisory
https://usn.ubuntu.com/3697-1/
Third Party Advisory
https://usn.ubuntu.com/3697-2/
Third Party Advisory