cbcvebase.
CVE-2018-16862
published 2018-11-26

CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file…

PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.53%
41.8th percentile
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.19.9-1 (bookworm)linux 4.19.9-1 (bookworm)
linuxlinux_kernel<= 4.14
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.4.0-142.1684.4.0-142.168
linuxlinux_kernel>= 0 < 4.15.0-58.644.15.0-58.64
redhatenterprise_linux

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.