Lucene search

K
f5F5F5:K36462841
HistoryJul 08, 2022 - 12:00 a.m.

K36462841 : Linux kernel vulnerability CVE-2018-18281

2022-07-0800:00:00
my.f5.com
36

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.5%

Security Advisory Description

Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19. (CVE-2018-18281)

Impact

An attacker may be able to overflow temporary memory resources resulting in improper access to physical memory pages or denial-of-service (DoS).