PT-2018-17205 · Linux · Linux Kernel

Andrey Konovalov

·

Published

2018-07-06

·

Updated

2023-07-19

·

CVE-2018-5873

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.11
Description: A race condition in the ns get path function in fs/nsfs.c can lead to a Use After Free condition when accessing files. This issue also affects Android releases from CAF using the Linux kernel before security patch level 2018-07-05.
Recommendations: For Linux kernel versions prior to 4.11, update to version 4.11 or later to resolve the issue. For Android releases from CAF using the Linux kernel, apply the security patch level 2018-07-05 or later.

Fix

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2018-5873

Affected Products

Linux Kernel