ISOMAN

CVE

CVE-2018-1066

The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cabfb3680f78981d26c078a26e5c748531257ebb
  2. http://www.securityfocus.com/bid/103378
  3. https://bugzilla.redhat.com/show_bug.cgi?id=1539599
  4. https://github.com/torvalds/linux/commit/cabfb3680f78981d26c078a26e5c748531257ebb
  5. https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html
  6. https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html
  7. https://patchwork.kernel.org/patch/10187633/
  8. https://usn.ubuntu.com/3880-1/
  9. https://usn.ubuntu.com/3880-2/
  10. https://www.debian.org/security/2018/dsa-4187
  11. https://www.debian.org/security/2018/dsa-4188
  12. http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cabfb3680f78981d26c078a26e5c748531257ebb
  13. http://www.securityfocus.com/bid/103378
  14. https://bugzilla.redhat.com/show_bug.cgi?id=1539599
  15. https://github.com/torvalds/linux/commit/cabfb3680f78981d26c078a26e5c748531257ebb
  16. https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html
  17. https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html
  18. https://patchwork.kernel.org/patch/10187633/
  19. https://usn.ubuntu.com/3880-1/
  20. https://usn.ubuntu.com/3880-2/