ZeroHour

CVE-2018-18397

PoC
CVSS 3.0
5.5 medium
EPSS
<1%p42
Published
()
Modified
Description

The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.

Vendors
linuxredhatcanonical
Products
linux kernel, openshift container platform, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, ubuntu linux
Weakness
CWE-863
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.