Red Hat Bugzilla – Bug 1631205
CVE-2018-17182 kernel: Use-after-free in the vmacache_flush_all function resulting in a possible privilege escalation
Last modified: 2018-10-08 10:00:24 EDT
A security flaw was discovered in the Linux kernel. The vmacache_flush_all() function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations. References: https://seclists.org/oss-sec/2018/q3/251 An upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7a9cdebdcc17e426fb5287e4a82db1dfe86339b2
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1631206]