Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12849
HistoryJan 15, 2019 - 9:22 a.m.

Denial Of Service (DoS)

2019-01-1509:22:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.0004 Low

EPSS

Percentile

0.4%

kernel-rt is vulnerable to denial of service (DoS) attacks. The vulnerability exists as the XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.

References