CVE-2018-10689: Blktrace Project Blktrace

Medium severity, CVSS 5.5. EPSS: 1.9% chance of exploitation in the next 30 days.

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

Affected products

Published 2018-05-03. Last modified 2026-06-17.