cbcvebase.
CVE-2018-18445
published 2018-10-17

CVE-2018-18445: In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.18.20-1 (bookworm)linux 4.18.20-1 (bookworm)
linuxlinux_kernel>= 0 < 4.18.20-14.18.20-1
linuxlinux_kernel>= 0 < 4.18.20-14.18.20-1
linuxlinux_kernel>= 0 < 4.18.20-14.18.20-1
linuxlinux_kernel>= 0 < 4.18.20-14.18.20-1
linuxlinux_kernel>= 0 < 4.15.0-43.464.15.0-43.46
linuxlinux_kernel>= 4.14.9 < 4.14.754.14.75
linuxlinux_kernel>= 4.15 < 4.18.134.18.13
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH