In the Linux kernel through 3.2, the rdsmessageallocsgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rdsrdmaextrasize function in net/rds/rdma.c).
[
{
"deprecated": false,
"target": {
"file": "net/rds/rdma.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c095508770aebf1b9218e77026e48345d719b17c",
"digest": {
"line_hashes": [
"108807829520385563416005798697693549915",
"80053667472337878567137693824014380094",
"284564634792760143986570930867193536345"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2018-5332-25545ca2"
},
{
"deprecated": false,
"target": {
"function": "rds_rdma_extra_size",
"file": "net/rds/rdma.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c095508770aebf1b9218e77026e48345d719b17c",
"digest": {
"function_hash": "84754218185271758958212327630104074875",
"length": 456.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2018-5332-9b036b19"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-5332.json"