Lucene search

K
redhatcveRedhat.comRH:CVE-2018-18445
HistoryApr 01, 2020 - 2:07 p.m.

CVE-2018-18445

2020-04-0114:07:09
redhat.com
access.redhat.com
15

0.001 Low

EPSS

Percentile

28.1%

A security flaw was found in the Linux kernel in the adjust_scalar_min_max_vals() function in kernel/bpf/verifier.c. A faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because this function mishandles 32-bit right shifts. A local unprivileged user cannot leverage this flaw, but as a privileged user (“root”) this can lead to a system panic and a denial of service or other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.