Linux 3.16~4.18.8 Affected By Another Potential Local Privilege Escalation Bug

Written by Michael Larabel in Linux Security on 19 September 2018 at 07:47 AM EDT. 47 Comments
LINUX SECURITY
From June of 2014 with Linux 3.16 until last week, the Linux kernel was affected by another potential local privilege escalation bug.

Fortunately, Linus Torvalds fixed it last week prior to taking his leave of absence. But the issue was fixed by Linus in removing the vmacache_flush_all code entirely on the basis of it being expensive, buggy, and unnecessary.

It was then posted to oss-sec on Tuesday that this vmacache code could lead to a a use-after-free situation and potentially local privilege escalation. The vulnerability is now published today as CVE-2018-17182. But if you switch now to the latest Linux kernel stable releases or are riding Linux Git, you should be in good shape.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week