[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-16871Date: (C)2019-08-08   (M)2024-04-19


A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: HIGH 
  
Reference:
RHSA-2019:2696
RHSA-2019:2730
RHSA-2020:0740
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871
https://security.netapp.com/advisory/ntap-20211004-0002/
https://support.f5.com/csp/article/K18657134
https://support.f5.com/csp/article/K18657134?utm_source=f5support&%3Butm_medium=RSS
https://support.f5.com/csp/article/K18657134?utm_source=f5support&utm_medium=RSS

CPE    1037
cpe:/o:linux:linux_kernel:3.6.10
cpe:/o:linux:linux_kernel:3.6.11
cpe:/o:linux:linux_kernel:4.7.6
cpe:/o:linux:linux_kernel:4.7.9
...
CWE    1
CWE-476
OVAL    11
oval:org.secpod.oval:def:66796
oval:org.secpod.oval:def:1504082
oval:org.secpod.oval:def:69511
oval:org.secpod.oval:def:205243
...

© SecPod Technologies