Integer overflow in Linux kernel - CVE-2018-8781
Published: May 2, 2018 / Updated: May 18, 2020
Vulnerability identifier: #VU12338
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8781
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c due to integer overflow. A local attacker can gain full read and write permissions on kernel physical pages and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c due to integer overflow. A local attacker can gain full read and write permissions on kernel physical pages and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Linux kernel
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
SUSE Linux
openSUSE Leap
kernel-alt (Red Hat package)
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
SUSE Linux
openSUSE Leap
kernel-alt (Red Hat package)
How to mitigate CVE-2018-8781
Update to version 4.15.1.
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a