CVE-2018-16884: Canonical Ubuntu Linux

High severity, CVSS 8.0. EPSS: 1.5% chance of exploitation in the next 30 days.

A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 3.7, before 3.16.65 (fixed in 3.16.65); from 3.17, before 3.18.133 (fixed in 3.18.133); from 3.19, before 4.4.171 (fixed in 4.4.171); from 4.5, before 4.9.151 (fixed in 4.9.151); from 4.10, before 4.14.94 (fixed in 4.14.94); from 4.15, before 4.19.16 (fixed in 4.19.16); …
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Mrg: version 2.0 only

Published 2018-12-18. Last modified 2026-06-17.