ISOMAN

CVE

CVE-2018-8822

Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

References

  1. http://www.openwall.com/lists/oss-security/2022/12/27/3
  2. http://www.securityfocus.com/bid/103476
  3. https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
  4. https://usn.ubuntu.com/3653-1/
  5. https://usn.ubuntu.com/3653-2/
  6. https://usn.ubuntu.com/3654-1/
  7. https://usn.ubuntu.com/3654-2/
  8. https://usn.ubuntu.com/3655-1/
  9. https://usn.ubuntu.com/3655-2/
  10. https://usn.ubuntu.com/3656-1/
  11. https://usn.ubuntu.com/3657-1/
  12. https://www.debian.org/security/2018/dsa-4187
  13. https://www.debian.org/security/2018/dsa-4188
  14. https://www.mail-archive.com/netdev%40vger.kernel.org/msg223373.html
  15. http://www.openwall.com/lists/oss-security/2022/12/27/3
  16. http://www.securityfocus.com/bid/103476
  17. https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
  18. https://usn.ubuntu.com/3653-1/
  19. https://usn.ubuntu.com/3653-2/
  20. https://usn.ubuntu.com/3654-1/