Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
BID:103605
CVE-2018-7566 |Info
Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
| Bugtraq ID: | 103605 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2018-7566 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 14 2018 12:00AM |
| Updated: | Oct 29 2018 12:00PM |
| Credit: | [email protected] |
| Vulnerable: |
Redhat Enterprise Mrg 2 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Oracle Linux 7 Oracle Linux 6.0 Linux kernel 4.15 |
| Not Vulnerable: | |
Discussion
Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
Linux Kernel is prone to a local buffer-overflow vulnerability it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Linux Kernel 4.15 is vulnerable; other versions may also be affected.
Linux Kernel is prone to a local buffer-overflow vulnerability it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Linux Kernel 4.15 is vulnerable; other versions may also be affected.
Exploit / POC
Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel 'snd_seq_write()' Function Local Buffer Overflow Vulnerability
References:
References:
- ALSA: seq: Fix racy pool initializations (Linux)
- Bug 1550142 - (CVE-2018-7566) CVE-2018-7566 kernel: race condition in snd_seq_wr (Red Hat Bugzilla)
- CVE-2018-7566 (Red Hat Bugzilla)
- Linux Homepage (Linux)
- Oracle Linux Bulletin - October 2018 (Oracle)