Linux Kernel RDS RCE Vulnerability
Security researchers have released details of a race condition vulnerability in the Linux kernel. A remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.
Summary
Security researchers have released details of a race condition vulnerability in the Linux kernel. A remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition on an affected device.
Affected platforms
The following platforms are known to be affected:
Threat details
The vulnerability appears to be a result of a flaw in the rds_tcp_kill_sock TCP/IP implementation in the kernel's net/rds/tcp.c stack. By sending specially crafted TCP packets a use-after-free error can be introduced, resulting in the race condition being induced.
At the time of publication, only distributions using Reliable Datagram Sockets (RDS) appear to be affected, although it is unclear why this is the case.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
The Linux Foundation have addressed this vulnerability in kernel version 5.0.8, which has been passed to distribution vendors for integration. Organisations are encouraged to contact their relevant suppliers to obtain and apply any updates. |
Last edited: 14 February 2020 2:44 pm