← Back

CVE-2018-8781

nvd nist
Published: Apr 23, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.

Affected (17)

Show all products
1 product
Linux Kernel
1 product
Ubuntu Linux
1 product
Debian Linux
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.17 to 3.18.103
From 3.19 to 4.1.52
From 3.4 to 3.16.57
From 4.10 to 4.14.31
From 4.15 to 4.15.14
From 4.2 to 4.4.125
From 4.5 to 4.9.91
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 17.10
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Version 9.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Version 7.0
Version 7.0

References (30)

Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Mailing ListThird Party Advisory
Source: cve@checkpoint.com
Issue TrackingPatchThird Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: cve@checkpoint.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.