CVE-2018-10902: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: affected versions not specified
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2018-08-21. Last modified 2026-07-07.