Red Hat Bugzilla – Bug 1611005
CVE-2018-14734 kernel: use-after-free in ucma_leave_multicast in drivers/infiniband/core/ucma.c
Last modified: 2018-09-10 02:23:06 EDT
A flaw was found in Linux Kernel in the ucma_leave_multicast() function in drivers/infiniband/core/ucma.c which allows to access a certain data structure after freeing it in ucma_process_join(). This allows an attacker to cause use-after-free bug and to induce kernel memory corruption, leading to a system crash or other unspecified impact. References: https://marc.info/?t=152787806300002&r=1&w=2 https://patchwork.kernel.org/patch/10444267/ An upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cb2595c1393b4a5211534e6f0a0fbad369e21ad8
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1611007]