CVE-2018-14613 PUBLISHED

An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-checker.c.

EPSS 0.10% · 28.5th percentile

Risk Scores

EPSS Score
0.10%
28.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws4.4.0-1016.25, 4.4.0-1018.27, 4.4.0-1020.29
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:16.04:LTSlinux-kvm4.4.0-1020.25, 4.4.0-1041.47, 4.4.0-1040.46
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:14.04:LTSlinux-aws4.4.0-1003.3, 4.4.0-1002.2, 0
Ubuntu:16.04:LTSlinux-oracle4.15.0-1009.11~16.04.1, 4.15.0-1011.13~16.04.1, 4.15.0-1013.15~16.04.1
Ubuntu:18.04:LTSlinux0, 4.15.0-55.60, 4.15.0-54.58
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1006.6, 0, 4.4.0-1003.3
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1035.37~16.04.1, 4.15.0-1036.38~16.04.1, 4.15.0-1039.41~16.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2
Ubuntu:20.04:LTSlinux-riscv5.4.0-33.37, 5.4.0-34.38, 5.4.0-36.41
Ubuntu:16.04:LTSlinux-gcp4.10.0-1004.4, 4.15.0-1037.39~16.04.1, 4.15.0-1036.38~16.04.1
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux4.4.0-91.114, 0, 4.2.0-16.19
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.4.0-1004.4, 5.3.0-1017.19
Ubuntu:16.04:LTSlinux-raspi24.4.0-1027.33, 4.4.0-1023.29, 4.4.0-1021.27
Ubuntu:18.04:LTSlinux-raspi24.15.0-1006.7, 4.15.0-1009.10, 4.15.0-1010.11
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1057.62~14.04.1, 4.15.0-1056.61~14.04.1, 4.15.0-1055.60~14.04.1
Ubuntu:18.04:LTSlinux-aws4.15.0-1005.5, 4.15.0-1023.23, 4.15.0-1021.21

…and 20 more

Timeline

References

Open in Interactive Console →