CVE-2018-18559: Linux Kernel
High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case involving a packet_do_bind unregister action followed by a packet_notifier register action. Later, packet_release operates on only one of the two applicable linked lists. The attacker can achieve Program Counter control.
Affected products
- Linux Linux Kernel: from 3.2.95, before 3.2.100 (fixed in 3.2.100); from 3.14.58, before 3.15 (fixed in 3.15); from 3.18.25, before 3.18.88 (fixed in 3.18.88); from 4.1.14, before 4.1.49 (fixed in 4.1.49); from 4.2.7, before 4.3 (fixed in 4.3); from 4.3.1, before 4.4.106 (fixed in 4.4.106); …
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat Openshift Container Platform: version 3.11 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-10-22. Last modified 2026-06-17.