Back

MEDIUM

kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service

Published Oct 8, 2018

Description

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

Affected products

Remediation

Red Hat statement

At this time this flaws reproduction environment is considered too extraordinary and will rarely be a feasable attack vector for most attackers. The IPSEC connection between connected hosts is a somewhat privileged operation with a shared secret between systems, Red Hat will unlikely fix this issue due to its significant setup complexity and unlikely configuration.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 8, 2018
Updated Aug 5, 2024
Reserved Oct 3, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 5, 2018