Vulnerability Description
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.2.102 |
| Debian | Debian Linux | 7.0 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:1854Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3083Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0641Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.102Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.51Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.25Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.15.8Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.121Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.87Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlThird Party Advisory
- https://secuniaresearch.flexerasoftware.com/advisories/81331/Third Party Advisory
- https://secuniaresearch.flexerasoftware.com/secunia_research/2018-2/Third Party Advisory
FAQ
What is CVE-2018-5803?
CVE-2018-5803 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can...
How severe is CVE-2018-5803?
CVE-2018-5803 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5803?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Redhat Virtualization Host, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server.