peter bassill · operator
$ cve CVE-2018-12714 JSON

CVE-2018-12714

9.8
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via crafted perf_event_open and mmap system calls.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.07% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2018-06-24
Last modified2026-06-17

Affected (1)

VendorProduct
linuxlinux kernel

References

→ the Explorer  ·  watch your stack  ·  NVD