CVE-2018-20836

CVSS v3.1 8.1 (High)
81% Progress
CVSS v2.0 9.3 (High)
93% Progress
EPSS 1.02 % (84th)
1.02% Progress
Affected Products 13
Advisories 25

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-05-07 14:29:00
(5 years ago)
Updated Date
2022-11-03 02:22:37
(22 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 3.16.72 version cpe:2.3:o:linux:linux_kernel < 3.16.72
  Linux Kernel from 3.17 version and prior 3.18.140 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.140
  Linux Kernel from 3.19 version and prior 4.4.180 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.4.180
  Linux Kernel from 4.5 version and prior 4.9.175 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.175
  Linux Kernel from 4.10 version and prior 4.14.118 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.118
  Linux Kernel from 4.15 version and prior 4.19.42 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.42

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm

Configuration #3

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #4

    CPE23 From Up To
  F5 Traffix Signaling Delivery Controller 5.0.0 cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.0.0
  F5 Traffix Signaling Delivery Controller 5.1.0 cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.1.0

Configuration #5

    CPE23 From Up To
  Netapp Active Iq Unified Manager for Vmware Vsphere from 9.5 version cpe:2.3:a:netapp:active_iq_unified_manager::*:*:*:*:vmware_vsphere >= 9.5
  Netapp Snapprotect cpe:2.3:a:netapp:snapprotect:-
  Netapp Solidfire & Hci Management Node cpe:2.3:a:netapp:solidfire_\%26_hci_management_node:-
  Netapp Solidfire & Hci Storage Node cpe:2.3:a:netapp:solidfire_\%26_hci_storage_node:-
  Netapp Storage Replication Adapter for Clustered Data Ontap For Vmware Vsphere cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:-:*:*:*:*:vmware_vsphere
  Netapp Vasa Provider for Clustered Data Ontap from 7.2 version cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap >= 7.2
  Netapp Virtual Storage Console for Vmware Vsphere from 7.2 version cpe:2.3:a:netapp:virtual_storage_console::*:*:*:*:vmware_vsphere >= 7.2
  Netapp Hci Compute Node cpe:2.3:h:netapp:hci_compute_node:-

Configuration #6

    CPE23 From Up To
  Opensuse Leap 15.0 cpe:2.3:o:opensuse:leap:15.0
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...