CVE-2018-5333
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
- Affected products
- Alt Linux, Linux Kernel, Suse, Ubuntu
- Linux Linux Kernel
- ≤ 4.14.13
- Fix
- Available
- CVSS 3.0
- 5.5 MEDIUM
- EPSS
- 7.7% (94th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2018-01-11
CVE-2018-5333 at NVD
8 known exploits for CVE-2018-5333
Proof-of-concept code and exploit modules indexed by Sploitus
kernel-exploits
kernel-exploits
kernel-exploit-factory
Exploit for Improper Access Control in Xen
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
Reliable Datagram Sockets (RDS) rds_atomic_free_op Privilege Escalation Exploit
Reliable Datagram Sockets (RDS) rds_atomic_free_op Privilege Escalation
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation