Information disclosure in Linux Kernel

Published: 2018-08-17
Risk Low
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2018-7754
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU14451

Risk: Low


CVE-ID: CVE-2018-7754

CWE-ID: CWE-200 - Information exposure

Exploit availability: No


The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to the aoedisk_debugfs_show function, as defined in the drivers/block/aoe/aoeblk.c source code file allows access to ffree:lines in a debugfs file. A local attacker can access the debugfs file to access sensitive address information, which could be used to conduct further attacks.


Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

Vulnerable software versions

Linux kernel: 4.10.0 - 4.16.4

CPE2.3 External links

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?