UBUNTU-CVE-2018-16880
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-16880
UBUNTU-CVE-2018-16880
Summary:
Details: A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.
References: https://ubuntu.com/security/CVE-2018-16880, https://www.openwall.com/lists/oss-security/2019/01/25/1, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b46a0bf78ad7b150ef5910da83859f7f5a514ffd, https://ubuntu.com/security/notices/USN-3903-1, https://ubuntu.com/security/notices/USN-3903-2, https://www.cve.org/CVERecord?id=CVE-2018-16880
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
