CVE-2018-20836: Canonical Ubuntu Linux
High severity, CVSS 8.1. EPSS: 5.1% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
Affected products
- Canonical Ubuntu Linux: version 16.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- F5 Traffix Signaling Delivery Controller: version 5.0.0 only; version 5.1.0 only
- Linux Linux Kernel: before 3.16.72 (fixed in 3.16.72); from 3.17, before 3.18.140 (fixed in 3.18.140); from 3.19, before 4.4.180 (fixed in 4.4.180); from 4.5, before 4.9.175 (fixed in 4.9.175); from 4.10, before 4.14.118 (fixed in 4.14.118); from 4.15, before 4.19.42 (fixed in 4.19.42)
- Netapp Active Iq Unified Manager: from 9.5
- Netapp Hci Compute Node: affected versions not specified
- Netapp Snapprotect: affected versions not specified
- Netapp Solidfire & Hci Management Node: affected versions not specified
- Netapp Solidfire & Hci Storage Node: affected versions not specified
- Netapp Storage Replication Adapter For Clustered Data Ontap: affected versions not specified
- Netapp Vasa Provider For Clustered Data Ontap: from 7.2
- Netapp Virtual Storage Console: from 7.2
- Opensuse Leap: version 15.0 only; version 15.1 only
Published 2019-05-07. Last modified 2026-06-17.