CVE-2018-1118: Infoleak
Last updated 4 July 2026
Other sources
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhostnewmsg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
— Launchpad
The Linux kernel does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhostnewmsg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
References:
https://lkml.org/lkml/2018/4/27/833
https://marc.info/?t=152484394400005&r=1&w=2 (and the next pages)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Kernelto a version that resolves this vulnerability.Fixed in 6.4 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernel (vhost/vhost.c)to a version that resolves this vulnerability.Fixed in 4.8 - Compensating control
Mitigate by preventing untrusted/local privileged users from accessing the /dev/vhost-net device file (e.g., restrict device-node permissions/ACLs or otherwise limit access to vhost-net).
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is CVE-2018-1118.
What is the severity of CVE-2018-1118?
CVE-2018-1118 has a severity level of low.
Which versions of Linux kernel are affected by CVE-2018-1118?
Linux kernel versions 4.8 and above are affected by CVE-2018-1118.
How can local privileged users exploit CVE-2018-1118?
Local privileged users can exploit CVE-2018-1118 to read kernel memory contents when reading from the /dev/vhost-n device.
Where can I find more information about CVE-2018-1118?
You can find more information about CVE-2018-1118 at the following references: [RHSA-2018:2948](https://access.redhat.com/errata/RHSA-2018:2948), [RHSA-2018:3083](https://access.redhat.com/errata/RHSA-2018:3083), [RHSA-2018:3096](https://access.redhat.com/errata/RHSA-2018:3096).