CVE-2018-8781: Integer Overflow

Published Apr 23, 2018
·
Updated

Last updated 4 July 2026

Other sources

The Linux kernel from version 3.4 through 4.15 has an integer overflow vulnerability in the drivers/gpu/drm/udl/udlfb.c:udlfbmmap() function. An attacker with access to the udldrmfb driver could exploit this to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.

Upstream Patch:

https://patchwork.freedesktop.org/patch/211845/

Mitre annoucement:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-8781

Red Hat

The udlfbmmap function in drivers/gpu/drm/udl/udlfb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.

Launchpad

Affected Software

19 affected componentsFixes available
redhat/kernel<4.16
4.16
Linux Linux kernel>=3.4<3.16.57
Linux Linux kernel>=3.17<3.18.103
Linux Linux kernel>=3.19<4.1.52
Linux Linux kernel>=4.2<4.4.125
Linux Linux kernel>=4.5<4.9.91
Linux Linux kernel>=4.10<4.14.31
Linux Linux kernel>=4.15<4.15.14
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
debian/linux
5.10.223-15.10.262-16.1.176-16.1.180-16.12.94-16.12.105-17.1.8-27.1.10-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 4.16
  2. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.105-1Fixed in 7.1.8-2Fixed in 7.1.10-1
  3. Upgrade

    Upgrade Linux kernel (drivers/gpu/drm/udl/udl_fb.c:udl_fb_mmap) to a version that resolves this vulnerability.

    Fixed in 4.15
  4. Compensating control

    Remove or restrict unprivileged/local access to the udldrmfb driver on affected systems until the kernel is patched (only local users with access are able to exploit the udl_fb_mmap integer-overflow in drivers/gpu/drm/udl/udl_fb.c from Linux kernel versions 3.4 through 4.15).

Event History

Apr 23, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:10 PM
Description
Jul 7, 2026
Data Sourced
via Ubuntu·11:17 AM
RemedyDescriptionSeverityAffected Software
Aug 27, 2026
Data Sourced
via Debian·12:21 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2018-8781?

The severity of CVE-2018-8781 is high with a severity value of 7.

2

What is the affected software for CVE-2018-8781?

The affected software for CVE-2018-8781 includes Ubuntu Linux with versions up to 4.16~, Ubuntu Linux Trusty with versions up to 3.13.0-151.201, Ubuntu Linux Xenial with versions up to 4.4.0-127.153, and Ubuntu Linux Artful with versions up to 4.13.0-45.50.

3

What is the remedy for CVE-2018-8781?

The remedy for CVE-2018-8781 is to update the Linux kernel to version 4.16~ or higher.

4

Where can I find more information about CVE-2018-8781?

You can find more information about CVE-2018-8781 at the following references: [Patchwork](https://patchwork.freedesktop.org/patch/211845/), [DSA-4187](https://www.debian.org/security/2018/dsa-4187), [DSA-4188](https://www.debian.org/security/2018/dsa-4188).

5

What is the CWE category of CVE-2018-8781?

The CWE category of CVE-2018-8781 is CWE-190 (Integer Overflow or Wraparound).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203