FlawAtlas
Search the atlas
UBUNTU-CVE-2018-15471 High

UBUNTU-CVE-2018-15471

An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.

Exploit probability Not scored
Published August 17, 2018
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux-azure

2 explicit affected versions

Ubuntu:16.04:LTS linux-azure

25 explicit affected versions

Ubuntu:16.04:LTS linux-azure-edge

5 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

22 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

42 explicit affected versions

Ubuntu:18.04:LTS linux

20 explicit affected versions

Ubuntu:18.04:LTS linux-aws

15 explicit affected versions

Ubuntu:18.04:LTS linux-azure

16 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

14 explicit affected versions

Ubuntu:18.04:LTS linux-kvm

15 explicit affected versions

Ubuntu:18.04:LTS linux-oem

12 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

17 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3819-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2018-15471

An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.

View original source

05 / REFERENCES

Further evidence