CVE-2018-16884: Use After Free
A flaw was found in the Linux kernel in the NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bcsvcprocess() use wrong back-channel id and cause a use-after-free. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://seclists.org/oss-sec/2018/q4/267
A proposed patchset:
https://patchwork.kernel.org/cover/10733767/
https://patchwork.kernel.org/patch/10733769/
Other sources
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bcsvcprocess() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.27.2.rt56.940.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.27.2.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.26.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.58.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.rt24.93.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.15.1.el8_0 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 1:3.10.0-693.58.1.rt56.652.el6 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-16884?
CVE-2018-16884 is considered a critical vulnerability due to its potential to cause kernel memory corruption.
How do I fix CVE-2018-16884?
To fix CVE-2018-16884, update the kernel to one of the patched versions specified by your distribution, such as kernel-rt or kernel for Red Hat and Debian.
What systems are affected by CVE-2018-16884?
CVE-2018-16884 affects various Linux kernel versions, particularly those in Red Hat and Debian distributions.
What kind of exploit is associated with CVE-2018-16884?
CVE-2018-16884 can be exploited by a malicious container user to cause a use-after-free condition and potential kernel memory corruption.
Is my kernel version safe from CVE-2018-16884?
To determine if your kernel version is safe from CVE-2018-16884, compare it with the known vulnerable versions listed in security advisories.