11 Linux Kernel CVEs in September 2018
Full month · Source: NIST NVD
In September 2018, 11 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 7 were rated High severity and 4 Medium. CVE-2018-14634 was confirmed as actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities catalog. September's 11 CVEs represent 6% of all 2018 Linux kernel CVEs , up from August's 10 (a 10% month-over-month increase) .
Actively Exploited CVEs — September 2018
1 CVE in CISA KEVCVE-2018-14634 is the only Linux kernel CVE from September 2018 confirmed as actively exploited in the wild. It carries a CVSS score of 7.8 (High severity) and is listed in the CISA Known Exploited Vulnerabilities catalog.
| CVE ID | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|
| CVE-2018-14634 | High KEV | 7.8 | 2018-09-25 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivile… |
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2018-14634 | linux | High KEV | 7.8 | 2018-09-25 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with … | |
| CVE-2018-17182 | linux | High | 7.8 | 2018-09-19 | An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles… | |
| CVE-2018-10853 | linux | High | 7.8 | 2018-09-11 | A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrs… | |
| CVE-2018-6555 | linux | High | 7.8 | 2018-09-04 | The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel … | |
| CVE-2018-5391 | linux | High | 7.5 | 2018-09-06 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packe… | |
| CVE-2018-14633 | linux | High | 7.0 | 2018-09-25 | A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a w… | |
| CVE-2018-14625 | linux | High | 7.0 | 2018-09-10 | A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from w… | |
| CVE-2018-16658 | linux | Medium | 6.1 | 2018-09-07 | An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/c… | |
| CVE-2018-14641 | linux | Medium | 5.9 | 2018-09-18 | A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 t… | |
| CVE-2018-16597 | linux | Medium | 5.5 | 2018-09-21 | An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by … | |
| CVE-2018-6554 | linux | Medium | 5.5 | 2018-09-04 | Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linu… |