CVE-2018-5873
published 2018-07-06CVE-2018-5873: An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After…
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.50%
40.4th percentile
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.11.6-1 (bookworm) | linux 4.11.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 3.19 < 4.1.50 | 4.1.50 |
| linux | linux_kernel | >= 4.10 < 4.11 | 4.11 |
| linux | linux_kernel | >= 4.2 < 4.4.116 | 4.4.116 |
| linux | linux_kernel | >= 4.5 < 4.9.82 | 4.9.82 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2018-5873: nsfs
vendor_android·2018-07-01·CVSS 7.0
CVE-2018-5873 [HIGH] CVE-2018-5873: nsfs
Android Security Bulletin 2018-07-01
CVE: CVE-2018-5873
Severity: HIGH
Type: EoP
Component: nsfs
References: A-77528487
QC-CR#2166382
Debian
CVE-2018-5873: linux - An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux ...
vendor_debian·2018·CVSS 7.0
CVE-2018-5873 [HIGH] CVE-2018-5873: linux - An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux ...
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
Scope: local
bookworm: resolved (fixed in 4.11.6-1)
bullseye: resolved (fixed in 4.11.6-1)
forky: resolved (fixed in 4.11.6-1)
sid: resolved (fixed in 4.11.6-1)
trixie: resolved (fixed in 4.11.6-1)
Red Hat
kernel: use-after-free in __ns_get_path()
vendor_redhat·2017-04-19·CVSS 7.0
CVE-2018-5873 [HIGH] CWE-416 kernel: use-after-free in __ns_get_path()
kernel: use-after-free in __ns_get_path()
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. A local attacker may be able to leverage this fault to escalate privileges on the system.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kern
GHSA
GHSA-w7cq-36jp-q6wg: An issue was discovered in the __ns_get_path function in fs/nsfs
ghsa_unreviewed·2022-05-14
CVE-2018-5873 [HIGH] CWE-362 GHSA-w7cq-36jp-q6wg: An issue was discovered in the __ns_get_path function in fs/nsfs
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
OSV
CVE-2018-5873: An issue was discovered in the __ns_get_path function in fs/nsfs
osv·2018-07-06·CVSS 7.0
CVE-2018-5873 [HIGH] CVE-2018-5873: An issue was discovered in the __ns_get_path function in fs/nsfs
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c516ff73557a8f7315066856c04b50383ac34https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34https://source.android.com/security/bulletin/2018-07-01https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95edba4a7afed6d2c4fa7e434bhttps://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletinhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c516ff73557a8f7315066856c04b50383ac34https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34https://source.android.com/security/bulletin/2018-07-01https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95edba4a7afed6d2c4fa7e434bhttps://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin
2018-07-06
Published