Vulnerability Description
In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.4.133 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html
- http://www.securitytracker.com/id/1041050Third Party AdvisoryVDB Entry
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.43Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.16.11Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.133Vendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.102Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlThird Party Advisory
- https://secuniaresearch.flexerasoftware.com/advisories/81540/Third Party Advisory
- https://secuniaresearch.flexerasoftware.com/secunia_research/2018-8/Third Party Advisory
- https://usn.ubuntu.com/3696-1/Third Party Advisory
- https://usn.ubuntu.com/3696-2/Third Party Advisory
FAQ
What is CVE-2018-5814?
CVE-2018-5814 is a vulnerability with a CVSS score of 7.0 (HIGH). In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after...
How severe is CVE-2018-5814?
CVE-2018-5814 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5814?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Canonical Ubuntu Linux.