CVE-2018-18445: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Linux Linux Kernel: from 4.14.9, before 4.14.75 (fixed in 4.14.75); from 4.15, before 4.18.13 (fixed in 4.18.13)
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only; version 7.6 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-10-17. Last modified 2026-06-17.