CVE-2018-5873

HIGH

Linux kernel <4.11 - Use After Free

Title source: llm
STIX 2.1

Description

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.

Exploits (1)

nomisec WORKING POC
by Trinadh465 · poc
https://github.com/Trinadh465/linux-4.1.15_CVE-2018-5873

Scores

CVSS v3 7.0
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362 CWE-416
Status published
Products (2)
google/android
linux/linux_kernel 3.19 - 4.1.50
Published Jul 06, 2018
Tracked Since Feb 18, 2026