CVE-2018-17182

HIGH

Linux kernel <4.18.8 - Use After Free

Title source: llm

Description

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.

Exploits (6)

nomisec WORKING POC 131 stars
by jas502n · poc
https://github.com/jas502n/CVE-2018-17182
github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/kernel/EXP-CVE-2018-17182
nomisec WORKING POC 1 stars
by likekabin · poc
https://github.com/likekabin/vmacache_CVE-2018-17182
nomisec WORKING POC
by jedai47 · poc
https://github.com/jedai47/cve-2018-17182
nomisec WORKING POC
by likekabin · poc
https://github.com/likekabin/CVE-2018-17182
exploitdb WORKING POC VERIFIED
by Google Security Research · textlocallinux
https://www.exploit-db.com/exploits/45497

Scores

CVSS v3 7.8
EPSS 0.0481
EPSS Percentile 89.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (8)

linux/linux_kernel < 3.16.58
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
netapp/active_iq_performance_analytics_services
netapp/element_software

Timeline

Published Sep 19, 2018
Tracked Since Feb 18, 2026