---
title: "CVE-2018-11412\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-11412?format=md
keywords: index, follow
---

# CVE-2018-11412

Publication date 24 May 2018

Last updated 4 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2018-11412?format=md#impact-score)

Toggle side navigation

## Description

In the Linux kernel 4.13 through 4.16.11, ext4\_read\_inline\_data() in
fs/ext4/inline.c performs a memcpy with an untrusted length value in
certain circumstances involving a crafted filesystem that stores the
system.data extended attribute value in a dedicated inode.

### From the Ubuntu Security Team

Jann Horn discovered that the ext4 filesystem implementation in the Linux
kernel did not properly keep xattr information consistent in some
situations. An attacker could use this to construct a malicious ext4 image
that, when mounted, could cause a denial of service (system crash) or
possibly execute arbitrary code.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-33.36 |
| 17.10 artful | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| linux-aws | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1020.20 |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| linux-azure | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1022.23 |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Fixed 4.15.0-1022.22~16.04.1 |
| 14.04 LTS trusty | Not affected |
| linux-azure-edge | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Fixed 4.15.0-1022.23 |
| 14.04 LTS trusty | Not in release |
| linux-euclid | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-flo | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-gcp | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1018.19 |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Fixed 4.15.0-1018.19~16.04.2 |
| 14.04 LTS trusty | Not in release |
| linux-gke | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Ignored end of standard support, was needs-triage |
| 14.04 LTS trusty | Not in release |
| linux-goldfish | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-grouper | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-hwe | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Fixed 4.15.0-33.36~16.04.1 |
| 14.04 LTS trusty | Not in release |
| linux-hwe-edge | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Fixed 4.15.0-33.36~16.04.1 |
| 14.04 LTS trusty | Not in release |
| linux-kvm | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1020.20 |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-lts-trusty | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-utopic | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-vivid | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-wily | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-xenial | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not affected |
| linux-maguro | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-mako | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-manta | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-oem | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1017.20 |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Ignored end of standard support, was needed |
| 14.04 LTS trusty | Not in release |
| linux-raspi2 | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Fixed 4.15.0-1021.23 |
| 17.10 artful | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-snapdragon | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2018-11412?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| linux | * Introduced by   [e50e512](https://git.kernel.org/linus/e50e5129f384ae282adebfb561189cdb19b81cee),   fixed by   [117166e](https://git.kernel.org/linus/117166efb1ee8f13c38f9e96b258f16d4923f888) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11412)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-11412)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-11412)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-11412)

### Related Ubuntu Security Notices (USN)

+ [USN-3752-2](https://usn.ubuntu.com/USN-3752-2)
+ Linux kernel (HWE) vulnerabilities
+ 24 August 2018

+ [USN-3752-1](https://usn.ubuntu.com/USN-3752-1)
+ Linux kernel vulnerabilities
+ 24 August 2018

+ [USN-3752-3](https://usn.ubuntu.com/USN-3752-3)
+ Linux kernel (Azure, GCP, OEM) vulnerabilities
+ 28 August 2018

### Other references

* <https://bugs.chromium.org/p/project-zero/issues/detail?id=1580>
* <https://bugzilla.kernel.org/show_bug.cgi?id=199803>
* <https://www.cve.org/CVERecord?id=CVE-2018-11412>
