CVE-2018-10840 PUBLISHED

Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.

EPSS 0.10% · 28.1th percentile

Risk Scores

EPSS Score
0.10%
28.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-azure4.15.0-1019.19, 4.15.0-1009.9, 4.15.0-1008.8
Ubuntu:18.04:LTSlinux-raspi24.15.0-1020.22, 4.15.0-1012.13, 4.15.0-1011.12
Ubuntu:16.04:LTSlinux-hwe4.13.0-43.48~16.04.1, 4.10.0-32.36~16.04.1, 4.10.0-33.37~16.04.1
Ubuntu:18.04:LTSlinux-gcp4.15.0-1010.10, 4.15.0-1009.9, 4.15.0-1008.8
Ubuntu:18.04:LTSlinux-oem0, 4.15.0-1002.3, 4.15.0-1004.5
Ubuntu:18.04:LTSlinux4.13.0-25.29, 0, 4.13.0-16.19
Ubuntu:16.04:LTSlinux-gcp0, 4.10.0-1004.4, 4.13.0-1015.19
Ubuntu:18.04:LTSlinux-aws4.15.0-1010.10, 4.15.0-1011.11, 4.15.0-1016.16
Ubuntu:16.04:LTSlinux-azure4.11.0-1009.9, 0, 4.13.0-1014.17
Ubuntu:18.04:LTSlinux-kvm4.15.0-1004.4, 4.15.0-1006.6, 4.15.0-1008.8

Timeline

References

Open in Interactive Console →