ZeroHour

CVE-2018-5814

CVSS 3.0
7.0 high
EPSS
<1%p31
Published
()
Modified
Description

In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.

Vendors
linuxdebiancanonical
Products
linux kernel, debian linux, ubuntu linux
Weakness
CWE-362
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.