UBUNTU-CVE-2018-8781
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-8781
UBUNTU-CVE-2018-8781
Summary:
Details: The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.
References: https://ubuntu.com/security/CVE-2018-8781, https://bugzilla.redhat.com/show_bug.cgi?id=1571062, https://patchwork.freedesktop.org/patch/211845/, https://ubuntu.com/security/notices/USN-3654-1, https://ubuntu.com/security/notices/USN-3654-2, https://ubuntu.com/security/notices/USN-3656-1, https://ubuntu.com/security/notices/USN-3677-1, https://ubuntu.com/security/notices/USN-3677-2, https://ubuntu.com/security/notices/USN-3674-1, https://ubuntu.com/security/notices/USN-3674-2, https://www.cve.org/CVERecord?id=CVE-2018-8781
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
