CVE-2018-5333 PUBLISHED

In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.

EPSS 1.29% · 79.6th percentile

Risk Scores

EPSS Score
1.29%
79.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws0, 4.4.0-1001.10, 4.4.0-1003.12
Ubuntu:16.04:LTSlinux-hwe0, 4.8.0-54.57~16.04.1, 4.13.0-39.44~16.04.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1028.32, 5.15.0-1027.31, 5.15.0-1026.30
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-13.29~14.04.1, 0, 4.4.0-14.30~14.04.2
Ubuntu:16.04:LTSlinux-raspi20, 4.2.0-1013.19, 4.4.0-1055.62
Ubuntu:14.04:LTSlinux-aws4.4.0-1014.14, 0, 4.4.0-1002.2
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1005.5, 4.4.0-1003.3, 4.4.0-1006.6
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.3.0-1007.8, 5.3.0-1014.16
Ubuntu:20.04:LTSlinux-gke5.4.0-1105.112, 5.4.0-1104.111, 5.4.0-1103.110
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1065.68+cvm2.1, 0, 5.4.0-1063.66+cvm2.2
Ubuntu:16.04:LTSlinux4.4.0-66.87, 4.4.0-64.85, 4.4.0-63.84
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-24.28, 5.4.0-26.30
Ubuntu:14.04:LTSlinux3.13.0-62.102, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1012.12, 4.4.0-1079.84, 4.4.0-1078.83
Ubuntu:16.04:LTSlinux-gcp4.13.0-1008.11, 4.13.0-1011.15, 4.10.0-1009.9
Ubuntu:16.04:LTSlinux-kvm4.4.0-1009.14, 4.4.0-1019.24, 4.4.0-1017.22
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:16.04:LTSlinux-azure4.13.0-1011.14, 4.13.0-1009.12, 4.13.0-1007.9
Ubuntu:16.04:LTSlinux-oem4.13.0-1008.9, 4.13.0-1010.11, 4.13.0-1012.13

…and 1 more

Timeline

References

Open in Interactive Console →