ZeroHour

CVE-2018-16884

CVSS 3.1
8.0 high
EPSS
1%p72
Published
()
Modified
Description

A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

Vendors
linuxredhatdebiancanonical
Products
linux kernel, enterprise linux, enterprise mrg, debian linux, ubuntu linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.