CVE-2018-16884 - CERT CVE
ID CVE-2018-16884
Sažetak A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
Reference
CVSS
Base: 6.7
Impact: 8.5
Exploitability:5.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL COMPLETE
CVSS vektor AV:A/AC:L/Au:S/C:P/I:P/A:C
Zadnje važnije ažuriranje 11-08-2023 - 19:12
Objavljeno 18-12-2018 - 22:29