cbcvebase.
CVE-2018-5814
published 2018-06-12

CVE-2018-5814: In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind…

PriorityP430high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.38%
30.8th percentile
In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.16.12-1 (bookworm)linux 4.16.12-1 (bookworm)
linuxlinux_kernel< 4.4.1334.4.133
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.4.0-130.1564.4.0-130.156
linuxlinux_kernel>= 0 < 4.15.0-33.364.15.0-33.36
linuxlinux_kernel4.10 – 4.14.43
linuxlinux_kernel4.15 – 4.16.11
linuxlinux_kernel4.5 – 4.9.102
linux_foundationlinux_kernel

CVSS provenance

nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.