CVE-2018-1118
Last modified
CVE-2018-1118 is a vulnerability of currently unknown severity. Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.8, < 4.18 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- https://access.redhat.com/errata/RHSA-2018:2948Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3083Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1118Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3762-1/Third Party Advisory
- https://usn.ubuntu.com/3762-2/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3083Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1118Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3762-1/Third Party Advisory
- https://usn.ubuntu.com/3762-2/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1118?
How severe is CVE-2018-1118?
How do I fix CVE-2018-1118?
Are you affected by CVE-2018-1118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
