4.6 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.001 Low
EPSS
Percentile
44.5%
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes
after dropping pagetable locks. If a syscall such as ftruncate() removes
entries from the pagetables of a task that is in the middle of mremap(), a
stale TLB entry can remain for a short time that permits access to a
physical page after it has been released back to the page allocator and
reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78,
4.18.16, 4.19.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | linux | < 4.15.0-44.47 | UNKNOWN |
ubuntu | 18.10 | noarch | linux | < 4.18.0-12.13 | UNKNOWN |
ubuntu | 14.04 | noarch | linux | < 3.13.0-165.215 | UNKNOWN |
ubuntu | 16.04 | noarch | linux | < 4.4.0-142.168 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-aws | < 4.15.0-1032.34 | UNKNOWN |
ubuntu | 18.10 | noarch | linux-aws | < 4.18.0-1006.7 | UNKNOWN |
ubuntu | 16.04 | noarch | linux-aws | < 4.4.0-1075.85 | UNKNOWN |
ubuntu | 16.04 | noarch | linux-aws-hwe | < 4.15.0-1032.34~16.04.1 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-azure | < 4.15.0-1037.39 | UNKNOWN |
ubuntu | 18.10 | noarch | linux-azure | < 4.18.0-1006.6 | UNKNOWN |
bugs.chromium.org/p/project-zero/issues/detail?id=1695
git.kernel.org/linus/eb66ae030829605d61fbef1909ce310e29f78821
launchpad.net/bugs/cve/CVE-2018-18281
nvd.nist.gov/vuln/detail/CVE-2018-18281
security-tracker.debian.org/tracker/CVE-2018-18281
ubuntu.com/security/notices/USN-3832-1
ubuntu.com/security/notices/USN-3835-1
ubuntu.com/security/notices/USN-3871-1
ubuntu.com/security/notices/USN-3871-3
ubuntu.com/security/notices/USN-3871-4
ubuntu.com/security/notices/USN-3871-5
ubuntu.com/security/notices/USN-3880-1
ubuntu.com/security/notices/USN-3880-2
www.cve.org/CVERecord?id=CVE-2018-18281
4.6 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.001 Low
EPSS
Percentile
44.5%