[CVE A/T v2] CVE-2018-1130 -- dccp oops

Andy Whitcroft apw at canonical.com
Thu Jun 7 08:34:33 UTC 2018


CVE-2018-1130
    It was discovered that a null pointer dereference vulnerability
    existed in the DCCP protocol implementation in the Linux kernel. A
    local attacker could use this to cause a denial of service (system
    crash).

Following this email are patch sets for artful and trusty, all patches
are clean cherry-picks.  For trusty there is a second fix also tickled
by the reproducer, the fix for this is already applied in artful.

Proposing for SRU to artful/linux and trusty/linux.

-apw




More information about the kernel-team mailing list