CVE-2018-6412 PUBLISHED

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

EPSS 0.24% · 47.3th percentile

Risk Scores

EPSS Score
0.24%
47.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips0, 4.4.0-1003.3, 4.4.0-1005.5
Ubuntu:20.04:LTSlinux-azure-fde0, 5.4.0-1063.66+cvm2.2, 5.4.0-1063.66+cvm3.2
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:20.04:LTSlinux-riscv5.4.0-37.42, 0, 5.4.0-24.28
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-gke5.4.0-1056.59, 5.4.0-1057.60, 5.4.0-1059.62
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:22.04:LTSlinux-riscv5.15.0-1015.17, 5.15.0-1028.32, 5.15.0-1014.16
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1007.8, 5.4.0-1006.6

Timeline

References

Open in Interactive Console →