CVE-2018-16880 PUBLISHED

A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.

EPSS 0.10% · 27.1th percentile

Risk Scores

EPSS Score
0.10%
27.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gcp-edge0, 4.18.0-1004.5~18.04.1, 4.18.0-1005.6~18.04.1
Ubuntu:18.04:LTSlinux-hwe0, 4.18.0-13.14~18.04.1, 4.18.0-14.15~18.04.1
Ubuntu:18.04:LTSlinux-azure4.15.0-1014.14, 4.15.0-1018.18, 4.15.0-1019.19

Timeline

References

Open in Interactive Console →