Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-11412

37
FAUCET Score

CVE-2018-11412 describes a memory corruption vulnerability in the Linux kernel versions 4.13 through 4.16.11, specifically within the ext4 filesystem's handling of inline data, which can be triggered by a crafted filesystem. This medium-severity flaw (CVSS 5.9) allows an unauthenticated attacker to cause a denial of service (system crash) with high impact and complexity, requiring no user interaction. While not listed on the KEV catalog or showing active exploitation in the wild, public exploit code exists (EDB-44832), though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.13, <= 4.16.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
16.35%
Probability of exploitation in next 30 days
EPSS Percentile
96.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-44832 · Jun 5, 2018
This CVE's current EPSS score of 0.1635 is in the 97th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-115.6.1.el7a
View patch

Vendor Advisories (1)

redhatCVE-2018-11412Moderate

kernel: out-of-bounds memcpy in fs/ext4/inline.c:ext4_read_inline_data() with crafted ext4 image

May 22, 2018

References

access.redhat.com / errata/RHSA-2019:0525
Third Party Advisory
bugs.chromium.org / p/project-zero/issues/detail
ExploitThird Party Advisory
bugzilla.kernel.org / show_bug.cgi
ExploitIssue TrackingThird Party Advisory
usn.ubuntu.com / 3752-1
Third Party Advisory
usn.ubuntu.com / 3752-2
Third Party Advisory
usn.ubuntu.com / 3752-3
Third Party Advisory
exploit-db.com / exploits/44832
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/104291
Third Party AdvisoryVDB Entry