CVE-2018-11243: Upx

High severity, CVSS 7.8. EPSS: 2.4% chance of exploitation in the next 30 days.

PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.

Affected products

  • Upx Upx: version 3.95 only

Published 2018-05-18. Last modified 2026-06-17.