CVE-2018-10840: Buffer Overflow
Last updated 24 July 2024
Other sources
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4xattrsetentry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10840?
CVE-2018-10840 is a vulnerability in the Linux kernel that allows for a heap-based buffer overflow in the ext4 file system.
How severe is CVE-2018-10840?
CVE-2018-10840 has a severity rating of high.
Which software versions are affected by CVE-2018-10840?
Ubuntu Linux versions 4.18~ and 4.15.0-33.36, as well as other Ubuntu packages, are affected by CVE-2018-10840.
How can I fix CVE-2018-10840?
To fix CVE-2018-10840, update your Linux kernel to version 4.18~ or 4.15.0-33.36, depending on your Ubuntu distribution.
Where can I find more information about CVE-2018-10840?
You can find more information about CVE-2018-10840 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104858), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:0162), [Ubuntu Security Notice](https://usn.ubuntu.com/3752-1/).