Use-after-free error in Linux kernel - CVE-2018-16884
Published: December 19, 2018 / Updated: December 19, 2018
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to bc_svc_process() use wrong back-channel id when NFS41+ shares mounted in different network namespaces at the same time. A remote attacker can use a malicious container to trigger use-after-free error and cause a system panic.