CVE-2018-6412: Linux Kernel

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

Affected products

  • Linux Linux Kernel: up to and including 4.15

Published 2018-01-31. Last modified 2026-06-17.