ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jun 28, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-perfUpgrade kernel-headersUpgrade kernel-develUpgrade kernel-sourceUpgrade perfUpgrade python-perfUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade kernel | May 18, 2021 | Jun 28, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub