CVE-2018-20511: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 4.18.11 (fixed in 4.18.11)

Published 2018-12-27. Last modified 2026-06-17.