CVE-2018-5803: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Linux Linux Kernel: before 3.2.102 (fixed in 3.2.102); from 3.3, before 4.1.51 (fixed in 4.1.51); from 4.3, before 4.9.87 (fixed in 4.9.87); from 4.10, before 4.14.25 (fixed in 4.14.25); from 4.15, before 4.15.8 (fixed in 4.15.8)
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-06-12. Last modified 2026-06-17.