Vulnerability Intelligence Report
CVE-2018-20669
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.57%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| canonical | ubuntu_linux | 14.04, 16.04, 18.04 |
| netapp | hci_management_node | all |
| netapp | snapprotect | all |
| netapp | solidfire | all |
| netapp | cn1610_firmware | all |
| netapp | cn1610 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.572%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-01-03T00:00:00 |
| Published | 2019-03-18T16:33:59 |
| Last Updated | 2024-08-05T12:05:17 |
Community Chatter & Buzz