Linux Kernel up to 4.10 net/rds/af_rds.c rds_recv_track_latency memory corruption

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 4.10 (Operating System). This issue affects the function rds_recv_track_latency of the file net/rds/af_rds.c. The manipulation with an unknown input leads to a memory corruption vulnerability (Out-of-Bounds). Using CWE to declare the problem leads to CWE-119. Impacted is confidentiality, integrity, and availability.

The weakness was published 08/19/2019. The identification of this vulnerability is CVE-2017-18552 since 08/18/2019. Technical details are known, but no exploit is available. The price for an exploit might be around USD $5k-$25k at the moment (estimation calculated on 08/19/2019).

Upgrading to version 4.11 eliminates this vulnerability.

Class: Memory corruption / Out-of-Bounds (CWE-119)
Local: Yes
Remote: No

Upgrade: Kernel 4.11

08/18/2019 CVE assigned
08/19/2019 +1 days Advisory disclosed
08/19/2019 +0 days VulDB entry created
08/19/2019 +0 days VulDB last update
CVE: CVE-2017-18552
