CVE-2018-18559: Linux Kernel

High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.

In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case involving a packet_do_bind unregister action followed by a packet_notifier register action. Later, packet_release operates on only one of the two applicable linked lists. The attacker can achieve Program Counter control.

Affected products

  • Linux Linux Kernel: from 3.2.95, before 3.2.100 (fixed in 3.2.100); from 3.14.58, before 3.15 (fixed in 3.15); from 3.18.25, before 3.18.88 (fixed in 3.18.88); from 4.1.14, before 4.1.49 (fixed in 4.1.49); from 4.2.7, before 4.3 (fixed in 4.3); from 4.3.1, before 4.4.106 (fixed in 4.4.106); …
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Openshift Container Platform: version 3.11 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-10-22. Last modified 2026-06-17.