CVE-2018-17182: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 3.2% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Linux Linux Kernel: from 3.16, before 3.16.58 (fixed in 3.16.58); from 3.17, before 3.18.123 (fixed in 3.18.123); from 3.19, before 4.4.157 (fixed in 4.4.157); from 4.5, before 4.9.128 (fixed in 4.9.128); from 4.10, before 4.14.71 (fixed in 4.14.71); from 4.15, before 4.18.9 (fixed in 4.18.9)
- Netapp Active Iq Performance Analytics Services: affected versions not specified
- Netapp Element Software: affected versions not specified
Published 2018-09-19. Last modified 2026-06-17.