CVE-2018-16871
An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · redhat/developer tools · redhat/mrg realtime · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · netapp/cloud backup · netapp/h410c firmware · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h300e firmware · netapp/h500e firmware · netapp/h700e firmware · netapp/h410s firmware
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2019:2696Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0740Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211004-0002/Third Party Advisory
- https://support.f5.com/csp/article/K18657134Third Party Advisory
- https://support.f5.com/csp/article/K18657134?utm_source=f5support&%3Butm_medium=RSS
- https://access.redhat.com/errata/RHSA-2019:2696Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0740Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211004-0002/Third Party Advisory
- https://support.f5.com/csp/article/K18657134Third Party Advisory
- https://support.f5.com/csp/article/K18657134?utm_source=f5support&%3Butm_medium=RSS
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.