kernel: NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c
Published Nov 4, 2019
7.5
HIGHCVSS 3.1
EPSS 3.64%
Description
An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.
Affected products
No data.
- ≥ 4.4.179 · < 4.4.195
No data.
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
While this is a network protocol being affected, the protocol is not available by default. A local process (or user) can trigger the protocol to be used which will then be loaded automatically would then have the vulnerable code loaded and the attack vector opened. To reiterate it is unlikely that most Linux systems will be using this protocol and therefore affected. Most systems do _NOT_ have this protocol used by services. This is an infrequently used module and if you wish to blacklist it, you can follow the steps outlined in https://access.redhat.com/solutions/41278 to blacklist the "rds_tcp" module for the relevant version of Red Hat Enterprise Linux.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-18680 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1772527 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.195 x_refsource_MISCExploitPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=91573ae4aed0a49660abdad4d42f2a0db995ee5e x_refsource_MISCPatchVendor Advisory
- https://github.com/torvalds/linux/commit/91573ae4aed0a49660abdad4d42f2a0db995ee5e x_refsource_MISCPatchThird Party Advisory
- https://lkml.org/lkml/2019/9/18/337 x_refsource_MISCExploitMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18680
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18680
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-18680 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1772527 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.195 | x_refsource_MISCExploitPatchVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=91573ae4aed0a49660abdad4d42f2a0db995ee5e | x_refsource_MISCPatchVendor Advisory | |
| https://github.com/torvalds/linux/commit/91573ae4aed0a49660abdad4d42f2a0db995ee5e | x_refsource_MISCPatchThird Party Advisory | |
| https://lkml.org/lkml/2019/9/18/337 | x_refsource_MISCExploitMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-18680 | ||
| https://security.netapp.com/advisory/ntap-20191205-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-18680 |
Change history (0)
No recorded changes yet.