CVE-2018-16871

Severity
7.5HIGH
EPSS
1.5%
top 18.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateMay 24

Description

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

NVDlinux/linux_kernel3.04.20
Debianlinux< 4.18.20-1+3
CVEListV5red_hat/kernel:all 3.x, all 4.x up to 4.20

Also affects: Enterprise Linux 7.0, 7.4, 7.6

🔴Vulnerability Details

3
GHSA
GHSA-h4fx-7429-jvf7: A flaw was found in the Linux kernel's NFS implementation, all versions 32022-05-24
CVEList
CVE-2018-16871: A flaw was found in the Linux kernel's NFS implementation, all versions 32019-07-30
OSV
CVE-2018-16871: A flaw was found in the Linux kernel's NFS implementation, all versions 32019-07-30

📋Vendor Advisories

2
Red Hat
kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence2019-06-03
Debian
CVE-2018-16871: linux - A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and ...2018

💬Community

2
Bugzilla
CVE-2018-16871 kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence [fedora-all]2019-06-03
Bugzilla
CVE-2018-16871 kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence2018-11-30
CVE-2018-16871 (HIGH CVSS 7.5) | A flaw was found in the Linux kerne | cvebase.io