CVE-2018-8781 is an integer overflow vulnerability in the udl_fb_mmap function of the Linux kernel's udldrmfb driver, affecting versions 3.4 through 4.15. This flaw allows local users with driver access to gain full read/write permissions on kernel physical pages, potentially leading to kernel-space code execution. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been identified, there has been some community discussion about this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.4, < 3.16.57CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.103CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.1.52CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.2, < 4.4.125CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.91CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.