CVE-2018-5814: Canonical Ubuntu Linux
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: before 4.4.133 (fixed in 4.4.133); from 4.5, up to and including 4.9.102; from 4.10, up to and including 4.14.43; from 4.15, up to and including 4.16.11
Published 2018-06-12. Last modified 2026-06-17.