VYPR
Medium severity4.7NVD Advisory· Published Jan 3, 2019· Updated Jun 17, 2026

CVE-2018-16885

CVE-2018-16885

Description

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Range: 7 3.10.x
  • Linux/Kernelcpe-rescue2 versions
    3.10.x as shipped with Red Hat Enterprise Linux 7+ 1 more
    • (no CPE)range: 3.10.x as shipped with Red Hat Enterprise Linux 7
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=3.10.0,<=3.10.90
  • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.