Wind River Support Network

HomeDefectsLIN1018-2354
Fixed

LIN1018-2354 : Security Advisory - linux - CVE-2018-14625

Created: Sep 16, 2018    Updated: Aug 6, 2019
Resolved Date: Aug 6, 2019
Found In Version: unknown
Fix Version: 10.18.44.9
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.

https://nvd.nist.gov/vuln/detail/CVE-2018-14625

CVEs


Live chat
Online