CVE-2018-11412: Canonical Ubuntu Linux
Medium severity, CVSS 5.9. EPSS: 15.8% chance of exploitation in the next 30 days.
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Linux Linux Kernel: from 4.13, up to and including 4.16.11
Published 2018-05-24. Last modified 2026-06-17.