Vulnerability Description
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 10.4 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041646Third Party AdvisoryVDB Entry
- https://security.freebsd.org/advisories/FreeBSD-SA-18:12.elf.ascPatchVendor Advisory
- http://www.securitytracker.com/id/1041646Third Party AdvisoryVDB Entry
- https://security.freebsd.org/advisories/FreeBSD-SA-18:12.elf.ascPatchVendor Advisory
FAQ
What is CVE-2018-6924?
CVE-2018-6924 is a vulnerability with a CVSS score of 7.1 (HIGH). In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kern...
How severe is CVE-2018-6924?
CVE-2018-6924 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6924?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.