Vulnerability Description
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.2.95 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 6.4 |
| Redhat | Enterprise Linux Server Eus | 6.7 |
| Redhat | Enterprise Linux Server Tus | 6.6 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Canonical | Ubuntu Linux | 14.04 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=73223ePatchVendor Advisory
- http://www.securityfocus.com/bid/104093Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2384Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2785Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2791Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2924Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2933Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3540Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3586Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3590Third Party Advisory
- https://github.com/torvalds/linux/commit/73223e4e2e3867ebf033a5a8eb2e5df0158ccc9PatchVendor Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxurThird Party Advisory
FAQ
What is CVE-2018-10675?
CVE-2018-10675 is a vulnerability with a CVSS score of 7.8 (HIGH). The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted...
How severe is CVE-2018-10675?
CVE-2018-10675 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10675?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Virtualization Host, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus.