CVE-2018-20669
moderate-risk
Published 2019-03-21
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (8)
References (16)
Broken Link
http://www.securityfocus.com/bid/106748
Third Party Advisory
https://access.redhat.com/security/cve/cve-2018-20669
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190404-0002/
Third Party Advisory
https://support.f5.com/csp/article/K32059550
Third Party Advisory
https://usn.ubuntu.com/4485-1/
Broken Link
http://www.securityfocus.com/bid/106748
Third Party Advisory
https://access.redhat.com/security/cve/cve-2018-20669
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190404-0002/
Third Party Advisory
https://support.f5.com/csp/article/K32059550
Third Party Advisory
https://usn.ubuntu.com/4485-1/
38
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
0/34 · Minimal
Exposure
14/34 · Moderate