CVE-2018-20961: Double Free
In the Linux kernel before 4.16.4, a double free vulnerability in the fmidisetalt function of drivers/usb/gadget/function/fmidi.c in the fmidi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.16.4
Event History
Frequently Asked Questions
What is CVE-2018-20961?
CVE-2018-20961 is a double free vulnerability in the Linux kernel before version 4.16.4.
How does CVE-2018-20961 affect Linux?
CVE-2018-20961 may allow attackers to cause a denial of service or possibly have other unspecified impacts on the Linux kernel before version 4.16.4.
Which versions of Linux are affected by CVE-2018-20961?
CVE-2018-20961 affects various versions of the Linux kernel including 4.15.0-1053.57, 4.17~, and 4.4.0-1127.135.
How can I fix the CVE-2018-20961 vulnerability?
To fix the CVE-2018-20961 vulnerability, update your Linux kernel to version 4.16.4 or later.
Where can I find more information about CVE-2018-20961?
You can find more information about CVE-2018-20961 in the Linux kernel ChangeLog-4.16.4, the git.kernel.org commit, and the GitHub commit.