CVE-2018-9568: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
  • Google Android: affected versions not specified
  • Linux Linux Kernel: before 3.10.108 (fixed in 3.10.108); from 3.11, before 3.16.58 (fixed in 3.16.58); from 3.17, before 3.18.77 (fixed in 3.18.77); from 3.19, before 4.1.46 (fixed in 4.1.46); from 4.2, before 4.4.94 (fixed in 4.4.94); from 4.5, before 4.9.55 (fixed in 4.9.55); …
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-12-06. Last modified 2026-06-17.