#VU15670 Information disclosure in Linux kernel - CVE-2018-18710
Published: October 30, 2018 / Updated: November 1, 2018
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the cdrom_ioctl_select_disc function, as defined in the drivers/cdrom/cdrom.c source code file due to boundary error when processing of user-supplied input. A local attacker can access the system, execute an application that submits malicious input to read arbitrary kernel memory on the system, which could be used to conduct additional attacks.