CVE-2018-10675: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only
  • Linux Linux Kernel: before 3.2.95 (fixed in 3.2.95); from 3.3, before 3.16.50 (fixed in 3.16.50); from 3.17, before 3.18.67 (fixed in 3.18.67); from 3.19, before 4.1.45 (fixed in 4.1.45); from 4.2, before 4.4.84 (fixed in 4.4.84); from 4.5, before 4.9.45 (fixed in 4.9.45); …
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only; version 6.5 only; version 6.6 only; version 7.2 only; version 7.3 only; version 7.4 only; …
  • Red Hat Enterprise Linux Server Eus: version 6.7 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-05-02. Last modified 2026-06-17.