CVE-2018-10689: Blktrace Project Blktrace
Medium severity, CVSS 5.5. EPSS: 1.9% chance of exploitation in the next 30 days.
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.
Affected products
- Blktrace Project Blktrace: version 1.2.0 only
Published 2018-05-03. Last modified 2026-06-17.