CVE-2018-7273 is a Linux kernel vulnerability affecting versions through 4.15.4, where the floppy driver inadvertently leaks kernel function and global variable addresses via printk calls. This information, accessible through dmesg, allows a local attacker to map kernel memory and potentially bypass security mechanisms like KASLR. Rated Medium (CVSS 5.5), the vulnerability requires local access and has a high impact on confidentiality, but no impact on integrity or availability. While not actively exploited in the wild, a Proof-of-Concept (PoC) exploit exists on ExploitDB, and there is some community discussion, indicating awareness among researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.15.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.