5.5
CVSSv3

CVE-2018-11508

Published: 28/05/2018 Updated: 27/03/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The compat_get_timex function in kernel/compat.c in the Linux kernel prior to 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

canonical ubuntu linux 17.10

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
A regression that caused boot failures was fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
A regression that caused boot failures was fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
A flaw was found in the compat_get_timex function in kernel/compatc in the Linux kernel A local user could use this flaw to obtain possibly sensitive information from kernel memory via adjtimex system call ...

Exploits

#define _GNU_SOURCE #define _BSD_SOURCE #include <sys/timexh> #include <stdioh> #include <stdinth> #include <sys/typesh> #include <sys/socketh> #include <sys/waith> #include <sys/ioctlh> #include <sys/mmanh> #include <sys/ipch> #include <sys/semh> #include <sys/stath> #inc ...