CVE-2018-18445

Updated: 2023-12-06

CWE: Out-of-bounds Read

Description:

In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.

CVSS3: 7.8


Vendor State

OS Vendor version Errata
RHEL 7 3.10.0-957.10.1.el7 RHSA-2019:0512
Ubuntu 18.04 4.15.0-43.46 USN-3847-1
Ubuntu 18.04 AWS 4.15.0-1031.33 USN-3847-1
Ubuntu 16.04 HWE 4.15.0-43.46~16.04.1 USN-3847-2
Ubuntu 16.04 AWS HWE 4.15.0-1031.33~16.04.1 USN-3847-2
CentOS 7 3.10.0-957.10.1.el7 CESA-2019:0512
CentOS 7 plus 3.10.0-957.10.1.el7.centos.plus CESA-2019:0512
Oracle Linux 7 3.10.0-957.10.1.el7 ELSA-2019-0512
Ubuntu 18.04 GCP 4.15.0-1026.27 USN-3847-1
Ubuntu 16.04 GCP 4.15.0-1026.27~16.04.1 USN-3847-2
Ubuntu 18.04 Azure 4.15.0-1036.38 USN-3847-1
Ubuntu 16.04 Azure 4.15.0-1036.38~16.04.1 USN-3847-2

KernelCare State

OS Original kernel version State
RHEL 7
3.10.0-957.1.3.el7 show all hide all
3.10.0-957.el7 3.10.0-957.5.1.el7
In Rollout
Ubuntu 18.04
4.15.0-42.45 show all hide all
4.15.0-33.36 4.15.0-24.26 4.15.0-36.39 4.15.0-34.37 4.15.0-39.42 4.15.0-32.35 4.15.0-20.21 4.15.0-29.31 4.15.0-31.33 4.15.0-35.38 4.15.0-38.41 4.15.0-23.25 4.15.0-22.24 4.15.0-30.32
In Rollout
Ubuntu 18.04 AWS
4.15.0-1027.27 show all hide all
4.15.0-1021.21 4.15.0-1023.23 4.15.0-1029.30
In Rollout
Ubuntu 16.04 HWE
4.15.0-29.31~16.04.1 show all hide all
4.15.0-35.38~16.04.1 4.15.0-38.41~16.04.1 4.15.0-24.26~16.04.1 4.15.0-34.37~16.04.1 4.15.0-39.42~16.04.1 4.15.0-42.45~16.04.1 4.15.0-33.36~16.04.1 4.15.0-30.32~16.04.1 4.15.0-36.39~16.04.1 4.15.0-32.35~16.04.1
In Rollout
Ubuntu 16.04 AWS HWE
4.15.0-1030.31~16.04.1
In Rollout
CentOS 7
3.10.0-957.5.1.el7 show all hide all
3.10.0-957.el7 3.10.0-957.1.3.el7
In Rollout
CentOS 7 plus
3.10.0-957.el7.centos.plus show all hide all
3.10.0-957.5.1.el7.centos.plus 3.10.0-957.1.3.el7.centos.plus
In Rollout
Oracle Linux 7
3.10.0-957.1.3.el7 show all hide all
3.10.0-957.el7 3.10.0-957.0.el7 3.10.0-957.5.1.el7
In Rollout
Proxmox VE 5
4.15.18-7-pve-4.15.18-27 show all hide all
4.15.10-1-pve_4.15.10-4 4.15.15-1-pve_4.15.15-6 4.15.17-1-pve_4.15.17-9 4.15.17-2-pve_4.15.17-10 4.15.18-1-pve_4.15.18-16 4.15.18-1-pve_4.15.18-17 4.15.18-1-pve_4.15.18-19 4.15.18-2-pve_4.15.18-21 4.15.18-4-pve_4.15.18-23 4.15.18-7-pve_4.15.18-26 4.15.18-9-pve_4.15.18-30 4.15.3-1-pve_4.15.3-1 4.15.18-6-pve_4.15.18-25 4.15.18-8-pve_4.15.18-28 4.15.18-1-pve_4.15.18-15 4.15.18-2-pve_4.15.18-20 4.15.17-3-pve_4.15.17-12 4.15.18-3-pve_4.15.18-22 4.15.18-5-pve_4.15.18-24
In Rollout
Ubuntu 18.04 GCP
4.15.0-1006.6 show all hide all
4.15.0-1014.14 4.15.0-1010.10 4.15.0-1015.15 4.15.0-1025.26 4.15.0-1024.25 4.15.0-1018.19 4.15.0-1021.22 4.15.0-1017.18 4.15.0-1009.9 4.15.0-1008.8 4.15.0-1019.20
In Rollout
Ubuntu 16.04 GCP
4.15.0-1024.25~16.04.2 show all hide all
4.15.0-1021.22~16.04.1 4.15.0-1019.20~16.04.1 4.15.0-1017.18~16.04.1 4.15.0-1018.19~16.04.2 4.15.0-1014.14~16.04.1 4.15.0-1025.26~16.04.1 4.15.0-1015.15~16.04.1
In Rollout
Endurance 7 eig 4.14
Ready For Release
Proofpoint
Ready For Release
OEL 7 Dell
Ready For Release
Ubuntu 18.04 Azure
4.15.0-1014.14 show all hide all
4.15.0-1031.32 4.15.0-1025.26 4.15.0-1012.12 4.15.0-1021.21 4.15.0-1022.23 4.15.0-1009.9 4.15.0-1018.18 4.15.0-1028.29 4.15.0-1030.31 4.15.0-1032.33 4.15.0-1035.36 4.15.0-1019.19 4.15.0-1013.13 4.15.0-1023.24
In Rollout
Ubuntu 16.04 Azure
4.15.0-1018.18~16.04.1 show all hide all
4.15.0-1028.29~16.04.1 4.15.0-1030.31~16.04.1 4.15.0-1032.33~16.04.1 4.15.0-1025.26~16.04.1 4.15.0-1019.19~16.04.1 4.15.0-1023.24~16.04.1 4.15.0-1014.14~16.04.1 4.15.0-1022.22~16.04.1 4.15.0-1035.36~16.04.1 4.15.0-1021.21~16.04.1 4.15.0-1031.32~16.04.1 4.15.0-1013.13~16.04.2
In Rollout