cbcvebase.
CVE-2018-20836
published 2019-05-07

CVE-2018-20836: An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

Affected

23 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.2.6-1 (bookworm)linux 5.2.6-1 (bookworm)
f5traffix_signaling_delivery_controller
f5traffix_signaling_delivery_controller
linuxlinux_kernel< 3.16.723.16.72
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 4.4.0-157.1854.4.0-157.185
linuxlinux_kernel>= 3.17 < 3.18.1403.18.140
linuxlinux_kernel>= 3.19 < 4.4.1804.4.180
linuxlinux_kernel>= 4.10 < 4.14.1184.14.118
linuxlinux_kernel>= 4.15 < 4.19.424.19.42
linuxlinux_kernel>= 4.5 < 4.9.1754.9.175
netappactive_iq_unified_manager>= 9.5
netappvasa_provider_for_clustered_data_ontap>= 7.2
netappvirtual_storage_console>= 7.2
opensuseleap
opensuseleap

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH