FlawAtlas
Search the atlas
UBUNTU-CVE-2018-1118 Moderate

UBUNTU-CVE-2018-1118

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

Exploit probability Not scored
Published May 10, 2018
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS linux-azure

21 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

19 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

39 explicit affected versions

Ubuntu:18.04:LTS linux

17 explicit affected versions

Ubuntu:18.04:LTS linux-aws

12 explicit affected versions

Ubuntu:18.04:LTS linux-azure

12 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

11 explicit affected versions

Ubuntu:18.04:LTS linux-kvm

12 explicit affected versions

Ubuntu:18.04:LTS linux-oem

9 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

13 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2018-1118

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

View original source

05 / REFERENCES

Further evidence