ZeroHour

CVE-2018-16658

CVSS 3.0
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.

Vendors
linuxcanonicaldebian
Products
linux kernel, ubuntu linux, debian linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.