ZeroHour

CVE-2018-17182

PoC
CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
Modified
Description

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.

Vendors
linuxcanonicaldebiannetapp
Products
linux kernel, ubuntu linux, debian linux, active iq performance analytics services, element software
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news