CVE-2018-16871

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:mrg_realtime:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:53

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2019:2696 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2696 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2730 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2730 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0740 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0740 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16871 - Issue Tracking, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20211004-0002/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20211004-0002/ - Third Party Advisory
References () https://support.f5.com/csp/article/K18657134 - Third Party Advisory () https://support.f5.com/csp/article/K18657134 - Third Party Advisory
References () https://support.f5.com/csp/article/K18657134?utm_source=f5support&amp%3Butm_medium=RSS - () https://support.f5.com/csp/article/K18657134?utm_source=f5support&amp%3Butm_medium=RSS -

Information

Published : 2019-07-30 17:15

Updated : 2024-11-21 03:53


NVD link : CVE-2018-16871

Mitre link : CVE-2018-16871

CVE.ORG link : CVE-2018-16871


JSON object : View

Products Affected

redhat

  • enterprise_linux_server
  • enterprise_linux_desktop
  • mrg_realtime
  • enterprise_linux_server_tus
  • enterprise_linux
  • developer_tools
  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • enterprise_linux_workstation
  • enterprise_linux_server_eus

netapp

  • h300s_firmware
  • h700e_firmware
  • h410s_firmware
  • h410c_firmware
  • h300e
  • h300s
  • h700s
  • cloud_backup
  • h500e_firmware
  • h300e_firmware
  • h410c
  • h410s
  • h500s_firmware
  • h700e
  • h500s
  • h500e
  • h700s_firmware

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference