CVE-2018-17182
HIGH 7.8EPSS 3.2%
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 3.21% chance of exploitation in the next 30 days, 87th percentile
- Published
- 2018-09-19
- Updated
- 2024-08-05
Proof-of-concept exploits (6)
- jas502n/CVE-2018-17182130★ · 2018-10-02
- jedai47/cve-2018-171820★ · 2023-04-07
- likekabin/CVE-2018-171820★ · 2018-10-01
- likekabin/vmacache_CVE-2018-171821★ · 2018-10-01
- likescam/CVE-2018-171820★ · 2018-10-01
- likescam/vmacache_CVE-2018-171821★ · 2018-10-01