CVE-2018-11412 describes a memory corruption vulnerability in the Linux kernel versions 4.13 through 4.16.11, specifically within the ext4 filesystem's handling of inline data, which can be triggered by a crafted filesystem. This medium-severity flaw (CVSS 5.9) allows an unauthenticated attacker to cause a denial of service (system crash) with high impact and complexity, requiring no user interaction. While not listed on the KEV catalog or showing active exploitation in the wild, public exploit code exists (EDB-44832), though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.13, <= 4.16.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.