Back to search
CVE-2018-7191
Published: May 17, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character. This is similar to CVE-2013-4343.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1743792
x_refsource_MISC
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1748846
x_refsource_MISC
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.14
x_refsource_MISC
108380
vdb-entry
x_refsource_BID
openSUSE-SU-2019:1479
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1570
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1579
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now