cbcvebase.
CVE-2018-10878
published 2018-07-26

CVE-2018-10878: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.75%
51.3th percentile
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.17.3-1 (bookworm)linux 4.17.3-1 (bookworm)
linuxlinux_kernel< 3.16.583.16.58
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.4.0-134.1604.4.0-134.160
linuxlinux_kernel>= 0 < 4.15.0-44.474.15.0-44.47
linuxlinux_kernel>= 0 < 4.15.0-45.484.15.0-45.48
linuxlinux_kernel>= 3.17 < 3.18.1243.18.124
linuxlinux_kernel>= 3.19 < 4.4.1404.4.140
linuxlinux_kernel>= 4.10 < 4.14.554.14.55
linuxlinux_kernel>= 4.15 < 4.17.64.17.6
linuxlinux_kernel>= 4.5 < 4.9.1124.9.112
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.04.8MEDIUMCVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv2.06.1MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.