{"containers":{"cna":{"affected":[{"product":"Linux Kernel","vendor":"Linux Kernel","versions":[{"status":"affected","version":"before 4.17"}]}],"datePublic":"2018-09-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2018-10-23T09:57:01.000Z","orgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","shortName":"canonical"},"references":[{"name":"USN-3776-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3776-1/"},{"name":"USN-3776-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3776-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","tags":["mailing-list","x_refsource_MLIST"],"url":"https://www.spinics.net/lists/stable/msg255035.html"},{"name":"USN-3777-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3777-1/"},{"name":"USN-3775-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3775-1/"},{"name":"[debian-lts-announce] 20181003 [SECURITY] [DLA 1531-1] linux-4.9 security update","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html"},{"name":"DSA-4308","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"https://www.debian.org/security/2018/dsa-4308"},{"name":"USN-3775-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3775-2/"},{"name":"105304","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/105304"},{"name":"USN-3777-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3777-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","tags":["mailing-list","x_refsource_MLIST"],"url":"https://www.spinics.net/lists/stable/msg255031.html"},{"name":"USN-3777-3","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/3777-3/"}],"source":{"discovery":"UNKNOWN"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@ubuntu.com","DATE_PUBLIC":"2018-09-04T15:00:00.000Z","ID":"CVE-2018-6555","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Linux Kernel","version":{"version_data":[{"version_value":"before 4.17"}]}}]},"vendor_name":"Linux Kernel"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-416: Use After Free"}]}]},"references":{"reference_data":[{"name":"USN-3776-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3776-1/"},{"name":"USN-3776-2","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3776-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","refsource":"MLIST","url":"https://www.spinics.net/lists/stable/msg255035.html"},{"name":"USN-3777-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3777-1/"},{"name":"USN-3775-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3775-1/"},{"name":"[debian-lts-announce] 20181003 [SECURITY] [DLA 1531-1] linux-4.9 security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html"},{"name":"DSA-4308","refsource":"DEBIAN","url":"https://www.debian.org/security/2018/dsa-4308"},{"name":"USN-3775-2","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3775-2/"},{"name":"105304","refsource":"BID","url":"http://www.securityfocus.com/bid/105304"},{"name":"USN-3777-2","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3777-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","refsource":"MLIST","url":"https://www.spinics.net/lists/stable/msg255031.html"},{"name":"USN-3777-3","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3777-3/"}]},"source":{"discovery":"UNKNOWN"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T06:10:10.169Z"},"title":"CVE Program Container","references":[{"name":"USN-3776-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3776-1/"},{"name":"USN-3776-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3776-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://www.spinics.net/lists/stable/msg255035.html"},{"name":"USN-3777-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3777-1/"},{"name":"USN-3775-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3775-1/"},{"name":"[debian-lts-announce] 20181003 [SECURITY] [DLA 1531-1] linux-4.9 security update","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html"},{"name":"DSA-4308","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"https://www.debian.org/security/2018/dsa-4308"},{"name":"USN-3775-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3775-2/"},{"name":"105304","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/105304"},{"name":"USN-3777-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3777-2/"},{"name":"[stable] 20180904 [PATCH 2/2] irda: Only insert new objects into the global database via setsockopt","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://www.spinics.net/lists/stable/msg255031.html"},{"name":"USN-3777-3","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/3777-3/"}]}]},"cveMetadata":{"assignerOrgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","assignerShortName":"canonical","cveId":"CVE-2018-6555","datePublished":"2018-09-04T18:00:00.000Z","dateReserved":"2018-02-02T00:00:00.000Z","dateUpdated":"2024-09-16T23:42:04.264Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}