CVE-2018-8822: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Linux Linux Kernel: from 2.6.12, before 3.2.102 (fixed in 3.2.102); from 3.3, before 3.16.57 (fixed in 3.16.57); from 3.17, before 3.18.103 (fixed in 3.18.103); from 3.19, before 4.1.52 (fixed in 4.1.52); from 4.2, before 4.4.125 (fixed in 4.4.125); from 4.5, before 4.9.91 (fixed in 4.9.91); …
Published 2018-03-20. Last modified 2026-06-17.