CVE-2018-7191: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character. This is similar to CVE-2013-4343.

Affected products

  • Linux Linux Kernel: before 4.13.14 (fixed in 4.13.14)

Published 2019-05-17. Last modified 2026-06-17.