The netfilter subsystem in the Linux kernel through 4.15.7 mishandles the case of a rule blob that contains a jump but lacks a user-defined chain, which allows local users to cause a denial of service (NULL pointer dereference) by leveraging the CAPNETRAW or CAPNETADMIN capability, related to arptdotable in net/ipv4/netfilter/arptables.c, iptdotable in net/ipv4/netfilter/iptables.c, and ip6tdotable in net/ipv6/netfilter/ip6_tables.c.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1065.json"
[
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "20337465244589366564563032066605708534",
"length": 1952.0
},
"id": "CVE-2018-1065-20582448",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/arp_tables.c",
"function": "arpt_do_table"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"267098411708975879490682388287852182033",
"322545398433438508842881697311787051721",
"199517846346341666409247919055393117719",
"88309668945300149247547678497620080117"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-37821ac3",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/arp_tables.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "235160877825476523764226128721804449057",
"length": 2489.0
},
"id": "CVE-2018-1065-48b20b1e",
"deprecated": false,
"target": {
"file": "net/ipv6/netfilter/ip6_tables.c",
"function": "ip6t_do_table"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"20785415055995936977563775315460943433",
"83506929054200280281909005797748083161",
"94546411138151356702463773687420555345",
"279200452245077818528937770998396745416",
"14895427997390334477419323098871281390"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-5a345705",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/ip_tables.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "117184925062851195049457544605304277496",
"length": 2622.0
},
"id": "CVE-2018-1065-8aca151a",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/ip_tables.c",
"function": "ipt_do_table"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"298622952119444134817747540161773996381",
"257533185739729801319730634252529174457",
"318351545704339156130607100681047869453",
"311972862483990108325905077469926855464"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-f1cfcc46",
"deprecated": false,
"target": {
"file": "net/ipv6/netfilter/ip6_tables.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1065.json"
[
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "20337465244589366564563032066605708534",
"length": 1952.0
},
"id": "CVE-2018-1065-4a66cf2e",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/arp_tables.c",
"function": "arpt_do_table"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "117184925062851195049457544605304277496",
"length": 2622.0
},
"id": "CVE-2018-1065-50928d89",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/ip_tables.c",
"function": "ipt_do_table"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"298622952119444134817747540161773996381",
"257533185739729801319730634252529174457",
"318351545704339156130607100681047869453",
"311972862483990108325905077469926855464"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-87e03df4",
"deprecated": false,
"target": {
"file": "net/ipv6/netfilter/ip6_tables.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"20785415055995936977563775315460943433",
"83506929054200280281909005797748083161",
"94546411138151356702463773687420555345",
"279200452245077818528937770998396745416",
"14895427997390334477419323098871281390"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-a15c9125",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/ip_tables.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"function_hash": "235160877825476523764226128721804449057",
"length": 2489.0
},
"id": "CVE-2018-1065-e8892595",
"deprecated": false,
"target": {
"file": "net/ipv6/netfilter/ip6_tables.c",
"function": "ip6t_do_table"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/57ebd808a97d7c5b1e1afb937c2db22beba3c1f8",
"digest": {
"line_hashes": [
"267098411708975879490682388287852182033",
"322545398433438508842881697311787051721",
"199517846346341666409247919055393117719",
"88309668945300149247547678497620080117"
],
"threshold": 0.9
},
"id": "CVE-2018-1065-f0482d1a",
"deprecated": false,
"target": {
"file": "net/ipv4/netfilter/arp_tables.c"
}
}
]