VDB
CVE-2018-12930
CVE-2018-12930
PUBLISHED
ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
EPSS 0.11% · 29.6th percentile
Risk Scores
EPSS Score
0.11%
29.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:24.04:LTS | linux-nvidia-6.11 | 6.11.0-1013.13, 0, 6.11.0-1002.2 |
| Ubuntu:22.04:LTS | linux-gcp-5.19 | 5.19.0-1020.22~22.04.2, *, 5.19.0-1030.32~22.04.1 |
| Ubuntu:20.04:LTS | linux-gke | 5.4.0-1043.45, 5.4.0-1044.46, 5.4.0-1046.48 |
| Ubuntu:Pro:18.04:LTS | linux-gcp-5.4 | 5.4.0-1080.87~18.04.1, 5.4.0-1078.84~18.04.1, 5.4.0-1073.78~18.04.1 |
| Ubuntu:20.04:LTS | linux-hwe-5.13 | 5.13.0-52.59~20.04.1, *, * |
| Ubuntu:Pro:FIPS:20.04:LTS | linux-gcp-fips | 5.4.0-1021.21+fips1, 0 |
| Ubuntu:Pro:16.04:LTS | linux-azure | 4.13.0-1006.8, *, 4.15.0-1075.80 |
| Ubuntu:Pro:14.04:LTS | linux-aws | 4.4.0-1134.140, 4.4.0-1102.107, 4.4.0-1101.106 |
| Ubuntu:22.04:LTS | linux-nvidia-tegra | 5.15.0-1009.9, 5.15.0-1026.26, 5.15.0-1036.36 |
| Ubuntu:16.04:LTS | linux-hwe-edge | 4.13.0-21.24~16.04.1, *, 4.15.0-23.25~16.04.1 |
| Ubuntu:22.04:LTS | linux-azure-fde | 5.15.0-1059.67.1, 5.15.0-1045.52.1, 5.15.0-1042.49.1 |
| Ubuntu:Pro:20.04:LTS | linux-hwe-5.15 | *, *, 5.15.0-164.174~20.04.1 |
| Ubuntu:25.10 | linux-raspi | 0, 6.14.0-1005.5, 6.17.0-1003.3 |
| Ubuntu:Pro:18.04:LTS | linux-aws-5.4 | *, 5.4.0-1109.118~18.04.1, 5.4.0-1110.119~18.04.1 |
| Ubuntu:24.04:LTS | linux-riscv | 6.5.0-9.9.1, 6.8.0-20.20.1, 6.8.0-28.28.1 |
| Ubuntu:Pro:FIPS-updates:20.04:LTS | linux-aws-fips | *, 5.4.0-1021.21+fips2, 5.4.0-1069.73+fips2 |
| Ubuntu:20.04:LTS | linux-aws-5.11 | *, *, 5.11.0-1028.31~20.04.1 |
| Ubuntu:24.04:LTS | linux-aws-6.17 | 6.17.0-1007.7~24.04.1, 0, 6.17.0-1005.5~24.04.2 |
| Ubuntu:24.04:LTS | linux-oem-6.14 | 6.14.0-1010.10, 0, 6.14.0-1013.13 |
| Ubuntu:20.04:LTS | linux-gcp-5.13 | 5.13.0-1030.36~20.04.1, 5.13.0-1025.30~20.04.1, 5.13.0-1024.29~20.04.1 |
…and 218 more
Timeline
- Jun 28, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-12930 third-party-advisory
- https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12930 third-party-advisory