CVE-2018-14619 is a critical flaw in the Linux kernel's crypto subsystem (before version 4.15-rc4) where improper handling of the "null skcipher" during memory deallocation could lead to a use-after-free vulnerability. This vulnerability, rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), allows a local authenticated user to crash the system or potentially escalate privileges. While no public exploit code or active exploitation has been observed, and media coverage is absent, there has been limited community discussion, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14, < 4.14.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.15:rc1:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.15:rc2:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.15:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.