imPC@ndo IT

Tracker / CVE-2018-8781

CVE-2018-8781

High 7.8

The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · 3.17 → 3.18.103
linux linux_kernel · 3.19 → 4.1.52
linux linux_kernel · 3.4 → 3.16.57
linux linux_kernel · 4.10 → 4.14.31
linux linux_kernel · 4.15 → 4.15.14
linux linux_kernel · 4.2 → 4.4.125
linux linux_kernel · 4.5 → 4.9.91
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_workstation

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References