CVE-2018-11508: Infoleak
Last updated 4 July 2026
Other sources
The compatgettimex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.16.9
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-11508.
What is the description of the vulnerability?
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
Which versions of Linux kernel are affected by this vulnerability?
Versions of the Linux kernel before 4.16.9 are affected by this vulnerability.
How can local users exploit this vulnerability?
Local users can exploit this vulnerability by using adjtimex to obtain sensitive information from kernel memory.
How can I fix this vulnerability?
To fix this vulnerability, update the Linux kernel to version 4.17 or later.