UBUNTU-CVE-2018-13406
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-13406
UBUNTU-CVE-2018-13406
Summary:
Details: An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.
References: https://ubuntu.com/security/CVE-2018-13406, https://git.kernel.org/linus/9f645bcc566a1e9f921bdae7528a01ced5bc3713, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9f645bcc566a1e9f921bdae7528a01ced5bc3713, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.4, https://github.com/torvalds/linux/commit/9f645bcc566a1e9f921bdae7528a01ced5bc3713, https://ubuntu.com/security/notices/USN-3752-1, https://ubuntu.com/security/notices/USN-3752-2, https://ubuntu.com/security/notices/USN-3753-1, https://ubuntu.com/security/notices/USN-3753-2, https://ubuntu.com/security/notices/USN-3754-1, https://ubuntu.com/security/notices/USN-3752-3, https://www.cve.org/CVERecord?id=CVE-2018-13406
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
