AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-18559

HIGH · CVSS 8.1 EPSS 2.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-10-22 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects Linux.

CVE
CVE-2018-18559
Severity
HIGH
CVSS
8.1
EPSS
2.61%
Linux

Original NVD Description

In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case involving a packet_do_bind unregister action followed by a packet_notifier register action. Later, packet_release operates on only one of the two applicable linked lists. The attacker can achieve Program Counter control.

Related CVEs

Other vulnerabilities affecting the same vendor(s)