NULL pointer dereference vulnerability in __netlink_ns_capable() function in Linux kernel before 4.15-rc8

NULL pointer dereference vulnerability in __netlink_ns_capable() function in Linux kernel before 4.15-rc8

CVE-2018-14646 · MEDIUM Severity

AV:L/AC:L/AU:N/C:N/I:N/A:C

The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.