CVE-2018-18445 PUBLISHED

In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.

EPSS 0.04% · 13.7th percentile

Risk Scores

EPSS Score
0.04%
13.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-azure4.15.0-1012.12, 4.15.0-1009.9, 4.15.0-1008.8
Ubuntu:18.04:LTSlinux-aws4.15.0-1023.23, 4.15.0-1029.30, 4.15.0-1027.27
Ubuntu:16.04:LTSlinux-azure4.13.0-1011.14, 0, 4.11.0-1009.9
Ubuntu:16.04:LTSlinux-gcp4.13.0-1019.23, 4.15.0-1014.14~16.04.1, 4.15.0-1015.15~16.04.1
Ubuntu:18.04:LTSlinux-oem4.15.0-1018.21, 4.15.0-1015.18, 4.15.0-1012.15
Ubuntu:16.04:LTSlinux-hwe4.13.0-36.40~16.04.1, 0, 4.8.0-36.36~16.04.1
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1030.31~16.04.1, 0
Ubuntu:18.04:LTSlinux-raspi24.15.0-1028.30, 4.15.0-1027.29, 4.15.0-1026.28
Ubuntu:18.04:LTSlinux-kvm0, 4.15.0-1002.2, 4.15.0-1003.3
Ubuntu:18.04:LTSlinux4.15.0-29.31, 4.15.0-30.32, 4.15.0-32.35
Ubuntu:14.04:LTSlinux-azure0, 4.15.0-1035.36~14.04.2, 4.15.0-1032.33~14.04.2
Ubuntu:18.04:LTSlinux-gcp4.15.0-1010.10, 4.15.0-1014.14, 4.15.0-1015.15

Timeline

References

Open in Interactive Console →