An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1715-1 | linux-4.9 security update |
![]() |
EUVD-2018-5349 | An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used. |
![]() |
USN-3752-1 | Linux kernel vulnerabilities |
![]() |
USN-3752-2 | Linux kernel (HWE) vulnerabilities |
![]() |
USN-3752-3 | Linux kernel (Azure, GCP, OEM) vulnerabilities |
![]() |
USN-3753-1 | Linux kernel vulnerabilities |
![]() |
USN-3753-2 | Linux kernel (Xenial HWE) vulnerabilities |
![]() |
USN-3754-1 | Linux kernel vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:00:35.177Z
Reserved: 2018-07-06T00:00:00
Link: CVE-2018-13406

No data.

Status : Modified
Published: 2018-07-06T14:29:01.287
Modified: 2024-11-21T03:47:02.733
Link: CVE-2018-13406


No data.