In the Linux kernel through 3.2, the rdsmessageallocsgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rdsrdmaextrasize function in net/rds/rdma.c).
[
{
"id": "CVE-2018-5332-25545ca2",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"108807829520385563416005798697693549915",
"80053667472337878567137693824014380094",
"284564634792760143986570930867193536345"
]
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c095508770aebf1b9218e77026e48345d719b17c",
"signature_type": "Line",
"target": {
"file": "net/rds/rdma.c"
}
},
{
"id": "CVE-2018-5332-9b036b19",
"signature_version": "v1",
"digest": {
"function_hash": "84754218185271758958212327630104074875",
"length": 456.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c095508770aebf1b9218e77026e48345d719b17c",
"signature_type": "Function",
"target": {
"file": "net/rds/rdma.c",
"function": "rds_rdma_extra_size"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-5332.json"
[
{
"id": "CVE-2018-5332-1cba99dd",
"signature_version": "v1",
"digest": {
"function_hash": "84754218185271758958212327630104074875",
"length": 456.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/c095508770aebf1b9218e77026e48345d719b17c",
"signature_type": "Function",
"target": {
"file": "net/rds/rdma.c",
"function": "rds_rdma_extra_size"
}
},
{
"id": "CVE-2018-5332-4c33b0ed",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"108807829520385563416005798697693549915",
"80053667472337878567137693824014380094",
"284564634792760143986570930867193536345"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/c095508770aebf1b9218e77026e48345d719b17c",
"signature_type": "Line",
"target": {
"file": "net/rds/rdma.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-5332.json"