CVE-2018-17182

HIGH

Linux kernel <4.18.8 - Use After Free

Title source: llm

Description

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Google Security Research · textlocallinux
https://www.exploit-db.com/exploits/45497
nomisec WORKING POC 131 stars
by jas502n · poc
https://github.com/jas502n/CVE-2018-17182
github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/kernel/EXP-CVE-2018-17182
nomisec WORKING POC 1 stars
by likekabin · poc
https://github.com/likekabin/vmacache_CVE-2018-17182
nomisec WORKING POC
by jedai47 · poc
https://github.com/jedai47/cve-2018-17182
nomisec WORKING POC
by likekabin · poc
https://github.com/likekabin/CVE-2018-17182

Scores

CVSS v3 7.8
EPSS 0.0851
EPSS Percentile 92.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (8)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
linux/linux_kernel 3.16 - 3.16.58
netapp/active_iq_performance_analytics_services
netapp/element_software
Published Sep 19, 2018
Tracked Since Feb 18, 2026