CVE-2018-5814 PUBLISHED

In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.

EPSS 0.03% · 7.3th percentile

Risk Scores

EPSS Score
0.03%
7.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-raspi24.4.0-1003.4, 4.4.0-1004.5, 4.4.0-1009.10
Ubuntu:20.04:LTSlinux-gke5.4.0-1033.35, 0, 5.4.0-1053.56
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1016.16~24.04.1, 6.11.0-1017.17~24.04.1, 0
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1064.67+cvm1.1, 5.4.0-1065.68+cvm2.1, 5.4.0-1067.70+cvm1.1
Ubuntu:18.04:LTSlinux-kvm4.15.0-1011.11, 0, 4.15.0-1002.2
Ubuntu:16.04:LTSlinux-azure0, 4.15.0-1021.21~16.04.1, 4.15.0-1019.19~16.04.1
Ubuntu:16.04:LTSlinux-gcp4.15.0-1017.18~16.04.1, 0, 4.10.0-1004.4
Ubuntu:24.04:LTSlinux-azure-6.116.11.0-1013.13~24.04.1, 0, 6.11.0-1008.8~24.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-28.32, 5.4.0-27.31, 5.4.0-26.30
Ubuntu:22.04:LTSlinux-riscv5.15.0-1027.31, 5.15.0-1028.32, 5.15.0-1026.30
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1006.6, 4.4.0-1005.5, 4.4.0-1003.3
Ubuntu:16.04:LTSlinux-kvm4.4.0-1026.31, 4.4.0-1023.28, 4.4.0-1021.26
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux-aws4.4.0-1020.29, 4.4.0-1017.26, 4.4.0-1016.25
Ubuntu:18.04:LTSlinux-snapdragon4.4.0-1081.86, 0, 4.4.0-1079.84
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-128.154~14.04.1, 4.4.0-127.153~14.04.1, 4.4.0-124.148~14.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-128.177, 3.13.0-129.178, 3.13.0-132.181
Ubuntu:18.04:LTSlinux-azure4.15.0-1012.12, 4.15.0-1009.9, 4.15.0-1008.8
Ubuntu:20.04:LTSlinux-raspi20, 5.4.0-1006.6, 5.4.0-1004.4

…and 12 more

Timeline

References

Open in Interactive Console →