UBUNTU-CVE-2018-16884
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-16884
UBUNTU-CVE-2018-16884
Summary:
Details: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
References: https://ubuntu.com/security/CVE-2018-16884, https://lore.kernel.org/linux-nfs/[email protected]/T/#m6b9e4d7efcc6b3564f9d53c051caf2370ae8e70a, https://ubuntu.com/security/notices/USN-3932-1, https://ubuntu.com/security/notices/USN-3932-2, https://ubuntu.com/security/notices/USN-3980-1, https://ubuntu.com/security/notices/USN-3981-1, https://ubuntu.com/security/notices/USN-3980-2, https://ubuntu.com/security/notices/USN-3981-2, https://www.cve.org/CVERecord?id=CVE-2018-16884
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
