In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x...
Vulnerability Description
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18445
Credits & Attribution
No credits recorded in the NVD database.
References
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.13
- https://usn.ubuntu.com/3847-1/
- https://usn.ubuntu.com/3835-1/
- https://access.redhat.com/errata/RHSA-2019:0512
- https://usn.ubuntu.com/3847-2/
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.75
- https://usn.ubuntu.com/3832-1/
- https://github.com/torvalds/linux/commit/b799207e1e1816b09e7a5920fbb2d5fcf6edd681
- https://usn.ubuntu.com/3847-3/
- https://access.redhat.com/errata/RHSA-2019:0514
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1686
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b799207e1e1816b09e7a5920fbb2d5fcf6edd681
- https://support.f5.com/csp/article/K38456756
More from linux
View All →Affected Vendor
linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.