Use-after-free error in Google Chrome - CVE-2018-6086
Published: April 19, 2018 / Updated: June 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free in Disk Cache. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
chromium
How to mitigate CVE-2018-6086
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- OpenSUSE Linux update for chromium
- Gentoo update for Chromium, Google Chrome
- Red Hat update for Google Chrome
- Debian update for chromium-browser
- OpenSUSE Linux update for Chromium
- SUSE Linux update for chromium
- Fedora EPEL 7 update for chromium
- Fedora 27 update for chromium
- Fedora 28 update for chromium
- Fedora EPEL 7 update for chromium