CVE-2018-16871
Last modified
CVE-2018-16871 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. EPSS estimates a 2.78% chance of exploitation in the next 30 days.
Description
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.0, <= 4.20 |
| Redhat | Developer Tools | 1.0 |
| Redhat | Mrg Realtime | 2.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 7.4 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.4 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Netapp | Cloud Backup | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H300e Firmware | All versions |
| Netapp | H500e Firmware | All versions |
| Netapp | H700e Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://access.redhat.com/errata/RHSA-2019:2696Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0740Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211004-0002/Third Party Advisory
- https://support.f5.com/csp/article/K18657134Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2696Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0740Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211004-0002/Third Party Advisory
- https://support.f5.com/csp/article/K18657134Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16871?
How severe is CVE-2018-16871?
How do I fix CVE-2018-16871?
Are you affected by CVE-2018-16871?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
