Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16871

Опубликовано: 30 июл. 2019
Источник: debian
EPSS Низкий

Описание

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.18.20-1package
linuxfixed4.9.144-1stretchpackage
linuxnot-affectedjessiepackage

Примечания

  • https://git.kernel.org/linus/01310bb7c9c98752cc763b36532fab028e0f8f81

  • https://bugzilla.redhat.com/show_bug.cgi?id=1655162

EPSS

Процентиль: 70%
0.00649
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS3: 7.5
redhat
около 6 лет назад

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS3: 7.5
nvd
почти 6 лет назад

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS3: 7.5
github
около 3 лет назад

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость реализации протокола NFS ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00649
Низкий