CVE-2018-16885 REJECTED

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.

EPSS 0.06% · 19.8th percentile

Risk Scores

EPSS Score
0.06%
19.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSlinux-aws4.15.0-1086.91, 4.15.0-1136.147, 4.15.0-1137.148
Ubuntu:Pro:18.04:LTSlinux-azure-edge4.18.0-1008.8~18.04.1, 5.0.0-1012.12~18.04.2, 0
Ubuntu:Pro:18.04:LTSlinux-kvm4.15.0-1152.157, 4.15.0-1150.155, 4.15.0-1164.169
Ubuntu:Pro:18.04:LTSlinux-gcp-edge0, 4.18.0-1004.5~18.04.1, 4.18.0-1005.6~18.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-70.91~14.04.1, 4.4.0-72.93~14.04.1, 4.4.0-271.305~14.04.1
Ubuntu:Pro:18.04:LTSlinux4.13.0-17.20, 0, 4.15.0-239.251
Ubuntu:Pro:16.04:LTSlinux-hwe-edge4.11.0-13.19~16.04.1, 0, 4.11.0-14.20~16.04.1
Ubuntu:Pro:18.04:LTSlinux-gcp4.15.0-1023.24, 4.15.0-1021.22, 4.15.0-1019.20
Ubuntu:Pro:18.04:LTSlinux-hwe5.3.0-72.68, 5.3.0-70.66, 5.3.0-69.65
Ubuntu:Pro:18.04:LTSlinux-oem4.15.0-1018.21, 0, 4.15.0-1002.3
Ubuntu:Pro:16.04:LTSlinux-hwe4.15.0-52.56~16.04.1, 4.15.0-176.185~16.04.1, 4.15.0-177.186~16.04.1
Ubuntu:Pro:18.04:LTSlinux-azure5.0.0-1031.33, 4.15.0-1002.2, 4.15.0-1003.3
Ubuntu:Pro:18.04:LTSlinux-hwe-edge5.0.0-15.16~18.04.1, 5.0.0-16.17~18.04.1, 5.0.0-17.18~18.04.1
Ubuntu:Pro:14.04:LTSlinux0, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:Pro:16.04:LTSlinux-azure0, 4.15.0-1187.202~16.04.1, 4.15.0-1186.201~16.04.1
Ubuntu:Pro:16.04:LTSlinux-gcp4.15.0-1019.20~16.04.1, 4.15.0-1021.22~16.04.1, 4.15.0-1023.24~16.04.1
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1129.135, 0, 4.4.0-1002.2
Ubuntu:Pro:16.04:LTSlinux-aws-hwe4.15.0-1113.120~16.04.1, 4.15.0-1182.195~16.04.1, 4.15.0-1151.164~16.04.1
Ubuntu:Pro:16.04:LTSlinux-aws4.4.0-1106.117, 4.4.0-1105.116, 4.4.0-1104.115
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1066.71~14.04.1, 4.15.0-1190.205~14.04.1, 4.15.0-1189.204~14.04.1

…and 2 more

Timeline

References

Open in Interactive Console →