cbcvebase.
CVE-2018-9568
published 2018-12-06

CVE-2018-9568: In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

Affected

23 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.13.10-1 (bookworm)linux 4.13.10-1 (bookworm)
googleandroid
google_incandroid
linuxlinux_kernel< 3.10.1083.10.108
linuxlinux_kernel>= 0 < 4.13.10-14.13.10-1
linuxlinux_kernel>= 0 < 4.13.10-14.13.10-1
linuxlinux_kernel>= 0 < 4.13.10-14.13.10-1
linuxlinux_kernel>= 0 < 4.13.10-14.13.10-1
linuxlinux_kernel>= 0 < 3.13.0-165.2153.13.0-165.215
linuxlinux_kernel>= 3.11 < 3.16.583.16.58
linuxlinux_kernel>= 3.17 < 3.18.773.18.77
linuxlinux_kernel>= 3.19 < 4.1.464.1.46
linuxlinux_kernel>= 4.10 < 4.13.64.13.6
linuxlinux_kernel>= 4.2 < 4.4.944.4.94
linuxlinux_kernel>= 4.5 < 4.9.554.9.55
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH