Vulnerability Description
The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.14 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:3651Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3666Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3843Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14646Issue TrackingPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4PatchThird Party Advisory
- https://marc.info/?l=linux-netdev&m=151500466401174&w=2PatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3651Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3666Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3843Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14646Issue TrackingPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4PatchThird Party Advisory
- https://marc.info/?l=linux-netdev&m=151500466401174&w=2PatchThird Party Advisory
FAQ
What is CVE-2018-14646?
CVE-2018-14646 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploi...
How severe is CVE-2018-14646?
CVE-2018-14646 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14646?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Server Eus.