Rewterz Threat Advisory – CVE-2018-10938 – Linux Kernel Infinite Loop Vulnerability

Thursday, September 6, 2018

A vulnerability in Linux Kernel, that can be exploited by people with malicious intent to cause a Denial of Service, has been patched.

 

IMPACT: MEDIUM

 

PUBLISH DATE: 06-09-2018

 

OVERVIEW

 

An error within the “cipso_v4_optptr()” function (net/ipv4/cipso_ipv4.c) of the Linux Kernel can be exploited to trigger an infinite loop. This leads to a Denial of Service, withholding an organization’s availability. The vulnerability has been patched in a recent update.

 

ANALYSIS

 

A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. An attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c by remotely sending a crafted network package. This leads to a denial-of-service.

 

An attacker needs to set up a certain non-default configuration of LSM (Linux Security Module) and NetLabel on a system in order to leverage this flaw. All the kernels with the cipso_v4_optptr() function which have not backported the upstream commit 40413955ee26 are vulnerable.

 

This attack is launched via network and may put an organization’s availability at stake if Denial of Service is successful. To combat this vulnerability, updates have been released by the vendor.

 

AFFECTED PRODUCTS

 

The vulnerability is reported in versions prior to 4.4.154 and prior to 4.9.125 along with some others.
• The Linux Kernel 4.4.x
• Linux Kernel 4.9.x
• Linux Kernel 4.0.5
• Linux Kernel 4.13

 

UPDATES

 

Update to version 4.4.154 or 4.9.125.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 15, November 2018 Rewterz Threat Advisory – Microsoft Windows Server 2008 and Windows 7 multiple vulnerabilities
  • 15, November 2018 Rewterz Threat Advisory – CVE-2018- 8416 – Microsoft .NET core security bypass vulnerability
  • 14, November 2018 Rewterz Threat Advisory – CVE-2018-8256 & CVE-2018-8415 – Windows PowerShell Multiple Vulnerabilities
  • 14, November 2018 Rewterz Threat Advisory – Microsoft Windows Server 2019 Multiple Vulnerabilities

Copyright © Rewterz. All rights reserved.