FlawAtlas
Search the atlas
UBUNTU-CVE-2018-16880 High

UBUNTU-CVE-2018-16880

A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.

Exploit probability Not scored
Published January 29, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-azure

22 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-edge

3 explicit affected versions

Ubuntu:18.04:LTS linux-hwe

3 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3903-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2018-16880

A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.

View original source

05 / REFERENCES

Further evidence