CVE-2018-8781: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Linux Linux Kernel: from 3.4, before 3.16.57 (fixed in 3.16.57); from 3.17, before 3.18.103 (fixed in 3.18.103); from 3.19, before 4.1.52 (fixed in 4.1.52); from 4.2, before 4.4.125 (fixed in 4.4.125); from 4.5, before 4.9.91 (fixed in 4.9.91); from 4.10, before 4.14.31 (fixed in 4.14.31); …
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-04-23. Last modified 2026-06-17.