CVE-2018-5333
MEDIUMLinux kernel <4.14.13 - Memory Corruption
Title source: llmDescription
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
Exploits (4)
github
WORKING POC
3 stars
by TamiiLambrado · cpoc
https://github.com/TamiiLambrado/CVE-pocs/tree/master/CVE-2018-5333-rds-nullderef.c
gitlab
by os-exploit · poc
https://gitlab.com/penetration-test-learn/10vuln/os-exploit/bcoles-kernel-exploits
References (15)
Scores
CVSS v3
5.5
EPSS
0.0129
EPSS Percentile
79.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-476
Status
published
Affected Products (7)
linux/linux_kernel
< 4.14.13
debian/debian_linux
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
Timeline
Published
Jan 11, 2018
Tracked Since
Feb 18, 2026