CVE-2018-7191 is a denial-of-service vulnerability affecting the Linux kernel before version 4.13.14, specifically within the tun subsystem. A local attacker can trigger a NULL pointer dereference and system panic by providing a specially crafted device name containing a '/' character during an ioctl(TUNSETIFF) call. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local privileges, with the primary impact being system availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.13.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.