CVE-2018-5873
Last modified
CVE-2018-5873 is a high-severity vulnerability rated 7/10 on the CVSS scale. An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions | |
| Linux | Linux Kernel | >= 3.19, < 4.1.50 |
| Linux | Linux Kernel | >= 4.2, < 4.4.116 |
| Linux | Linux Kernel | >= 4.5, < 4.9.82 |
| Linux | Linux Kernel | >= 4.10, < 4.11 |
References
- https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34Patch, Third Party Advisory
- https://source.android.com/security/bulletin/2018-07-01Vendor Advisory
- https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34Patch, Third Party Advisory
- https://source.android.com/security/bulletin/2018-07-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5873?
How severe is CVE-2018-5873?
How do I fix CVE-2018-5873?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5867Lack of checking input size can lead to buffer overflow In W…
- CVE-2018-5868Lack of checking input size can lead to buffer overflow In W…
- CVE-2018-5869Improper input validation in the QTEE keymaster app can lead…
- CVE-2018-5870While loading a service image, an untrusted pointer derefere…
- CVE-2018-5871In Snapdragon (Automobile, Mobile, Wear) in version MDM9206,…
- CVE-2018-5872While parsing over-the-air information elements in all Andro…
- CVE-2018-5874While parsing an mp4 file, a stack-based buffer overflow can…
- CVE-2018-5875While parsing an mp4 file, an integer overflow leading to a …
- CVE-2018-5876While parsing an mp4 file, a buffer overflow can occur in Sn…
- CVE-2018-5877In the device programmer target-side code for firehose, a st…
- CVE-2018-5878While sending the response to a RIL_REQUEST_GET_SMSC_ADDRESS…
- CVE-2018-5879Improper length check while processing an MQTT message can l…
Are you affected by CVE-2018-5873?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
