CVE-2018-16884 Details
Description
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.7, < 3.16.65 >= 3.17, < 3.18.133 >= 3.19, < 4.4.171 >= 4.5, < 4.9.151 >= 4.10, < 4.14.94 >= 4.15, < 4.19.16 >= 4.20, < 4.20.3 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 |
CPE
Remediation
| |
| redhat enterprise mrg | 2.0 |
CPE
Remediation
| |
| debian debian linux | 8.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 |
CPE
Remediation
| |
Change History
28 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 11, 2023 | Reanalysis | [email protected] |
| May 16, 2023 | Modified Analysis | [email protected] |
| Feb 13, 2023 | CVE Modified | [email protected] |
| Feb 2, 2023 | CVE Modified | [email protected] |
| Jul 15, 2021 | CPE Deprecation Remap | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Jan 30, 2020 | CVE Modified | [email protected] |
| Nov 6, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 11, 2019 | CVE Modified | [email protected] |
| Sep 10, 2019 | CVE Modified | [email protected] |
| Jul 29, 2019 | CVE Modified | [email protected] |
| May 29, 2019 | CVE Modified | [email protected] |
| May 21, 2019 | CVE Modified | [email protected] |
| May 14, 2019 | CVE Modified | [email protected] |
| May 10, 2019 | Modified Analysis | [email protected] |
| May 3, 2019 | CVE Modified | [email protected] |
| Apr 9, 2019 | CVE Modified | [email protected] |
| Apr 3, 2019 | CVE Modified | [email protected] |
| Apr 1, 2019 | CVE Modified | [email protected] |
| Mar 28, 2019 | Modified Analysis | [email protected] |
| Mar 27, 2019 | CVE Modified | [email protected] |
| Jan 30, 2019 | Initial Analysis | [email protected] |
| Dec 21, 2018 | CVE Modified | [email protected] |
| Dec 20, 2018 | CVE Modified | [email protected] |