CVE-2018-1065 is a denial-of-service vulnerability affecting the netfilter subsystem in the Linux kernel through version 4.15.7. It arises from improper handling of netfilter rule blobs containing a jump but lacking a user-defined chain, specifically within the arp_tables.c, ip_tables.c, and ip6_tables.c files. The vulnerability has a CVSS v3.0 score of 4.7 (Medium), indicating a local attack vector with high attack complexity, requiring CAP_NET_RAW or CAP_NET_ADMIN capabilities, and leading to a NULL pointer dereference for a denial-of-service impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness and limited exploitation interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.15.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.