CVE-2018-16884 is a use-after-free vulnerability in the Linux kernel's NFS41+ subsystem, affecting Canonical, Debian, Linux, and Red Hat distributions. It arises when NFS41+ shares are mounted in different network namespaces simultaneously, leading to incorrect back-channel ID usage and potential host kernel memory corruption and system panic. With a CVSS score of 8.0 (HIGH), this flaw can be exploited by a low-privileged attacker on an adjacent network with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability, and privilege escalation cannot be ruled out. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has seen minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.7, < 3.16.65CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.133CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.4.171CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.151CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.94CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.