SB2020122411 - Denial of service in Linux kernel in F5 BIG-IP products 



SB2020122411 - Denial of service in Linux kernel in F5 BIG-IP products

Published: December 24, 2020

Security Bulletin ID SB2020122411
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use-after-free error (CVE-ID: CVE-2018-10675)

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the do_get_mempolicy function in mm/mempolicy.c due to use-after-free error. A local attacker can use specially crafted system calls, trigger memory corruption and cause the service to crash.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.