CVE-2018-18281: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 3.2, before 4.9.135 (fixed in 4.9.135); from 4.9.136, before 4.14.78 (fixed in 4.14.78); from 4.14.79, before 4.18.16 (fixed in 4.18.16); from 4.18.17, before 4.19 (fixed in 4.19)
Published 2018-10-30. Last modified 2026-06-17.