SB2018030208 - Denial of service in Linux Kernel
Published: March 2, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: CVE-2017-18204)
The vulnerability allows a local attacker to cause DoS condition on the target system.The weakness exists in the ocfs2_setattr function and is due to boundary error. A local attacker can submit a crafted DIO request, trigger memory corruption and cause the service to crash.
2) Memory corruption (CVE-ID: CVE-2018-5803)
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the _sctp_make_chunk() function due to boundary error. A local attacker can submit a crafted SCTP packet, trigger memory corruption and cause the service to crash.
Remediation
Install update from vendor's website.