cbcvebase.
CVE-2018-18653
published 2018-10-26

CVE-2018-18653: The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users to bypass intended Secure Boot…

PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.5th percentile
The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users to bypass intended Secure Boot restrictions and execute untrusted code by loading arbitrary kernel modules. This occurs because a modified kernel/module.c, in conjunction with certain configuration options, leads to mishandling of the result of signature verification.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianlinux< linux 5.4.6-1 (bookworm)linux 5.4.6-1 (bookworm)
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
paloaltopan-os

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.