cbcvebase.
CVE-2018-16884
published 2018-12-18

CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use…

PriorityP341high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
1.46%
70.5th percentile
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.19.16-1 (bookworm)linux 4.19.16-1 (bookworm)
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.19.16-14.19.16-1
linuxlinux_kernel>= 0 < 4.4.0-145.1714.4.0-145.171
linuxlinux_kernel>= 0 < 4.15.0-50.544.15.0-50.54
linuxlinux_kernel>= 3.17 < 3.18.1333.18.133
linuxlinux_kernel>= 3.19 < 4.4.1714.4.171
linuxlinux_kernel>= 3.7 < 3.16.653.16.65
linuxlinux_kernel>= 4.10 < 4.14.944.14.94
linuxlinux_kernel>= 4.15 < 4.19.164.19.16
linuxlinux_kernel>= 4.20 < 4.20.34.20.3
linuxlinux_kernel>= 4.5 < 4.9.1514.9.151
redhatenterprise_linux
redhatenterprise_mrg

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H
nvdv2.06.7MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:C
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.