ID:2692 - Exploit for Integer overflow in Linux kernel - CVE-2018-8781

 
Main Vulnerability Database Exploits ID:2692 - Exploit for Integer overflow in Linux kernel - CVE-2018-8781

ID:2692 - Exploit for Integer overflow in Linux kernel - CVE-2018-8781

Published: May 18, 2020


Vulnerability identifier: #VU12338
Vulnerability risk: Low
CVE-ID: CVE-2018-8781
CWE-ID: CWE-190
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c due to integer overflow. A local attacker can gain full read and write permissions on kernel physical pages and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Remediation

Update to version 4.15.1.