---
title: "CVE-2018-15471\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-15471?format=md
keywords: index, follow
---

# CVE-2018-15471

Publication date 17 August 2018

Last updated 4 July 2026

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2018-15471?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in xenvif\_set\_hash\_mapping in
drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used
in Xen through 4.11.x and other products. The Linux netback driver allows
frontends to control mapping of requests to request queues. When processing
a request to set or change this mapping, some input validation (e.g., for
an integer overflow) was missing or flawed, leading to OOB access in hash
handling. A malicious or buggy frontend may cause the (usually privileged)
backend to make out of bounds memory accesses, potentially resulting in one
or more of privilege escalation, Denial of Service (DoS), or information
leaks.

### From the Ubuntu Security Team

Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 18.10 cosmic | Fixed 4.18.0-11.12 |
| 18.04 LTS bionic | Fixed 4.15.0-39.42 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| linux-aws | 18.10 cosmic | Fixed 4.18.0-1004.5 |
| 18.04 LTS bionic | Fixed 4.15.0-1027.27 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| linux-aws-hwe | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-azure | 18.10 cosmic | Fixed 4.18.0-1006.6 |
| 18.04 LTS bionic | Fixed 4.15.0-1031.32 |
| 16.04 LTS xenial | Fixed 4.15.0-1031.32~16.04.1 |
| 14.04 LTS trusty | Fixed 4.15.0-1031.32~14.04.1 |
| linux-azure-edge | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Fixed 4.18.0-1006.6~16.04.2 |
| 14.04 LTS trusty | Not in release |
| linux-euclid | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-flo | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-gcp | 18.10 cosmic | Fixed 4.18.0-1003.4 |
| 18.04 LTS bionic | Fixed 4.15.0-1024.25 |
| 16.04 LTS xenial | Fixed 4.15.0-1024.25~16.04.2 |
| 14.04 LTS trusty | Not in release |
| linux-gcp-edge | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-gke | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Not in release |
| linux-goldfish | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-grouper | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-hwe | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Fixed 4.15.0-39.42~16.04.1 |
| 14.04 LTS trusty | Not in release |
| linux-hwe-edge | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Fixed 4.15.0-39.42~16.04.1 |
| 14.04 LTS trusty | Not in release |
| linux-kvm | 18.10 cosmic | Fixed 4.18.0-1004.4 |
| 18.04 LTS bionic | Fixed 4.15.0-1026.26 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-lts-trusty | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-utopic | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-vivid | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-wily | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-lts-xenial | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not affected |
| linux-maguro | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-mako | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-manta | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| linux-oem | 18.10 cosmic | Fixed 4.15.0-1026.31 |
| 18.04 LTS bionic | Fixed 4.15.0-1026.31 |
| 16.04 LTS xenial | Ignored end of standard support, was needed |
| 14.04 LTS trusty | Not in release |
| linux-oracle | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-raspi2 | 18.10 cosmic | Fixed 4.18.0-1006.8 |
| 18.04 LTS bionic | Fixed 4.15.0-1028.30 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| linux-snapdragon | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2018-15471?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| linux | * Introduced by   [40d8abd](https://git.kernel.org/linus/40d8abdee806d496a60ee607a6d01b1cd7fabaf0),   fixed by   [780e83c](https://git.kernel.org/linus/780e83c259fc33e8959fed8dfdad17e378d72b62) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15471)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-15471)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-15471)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-15471)

### Related Ubuntu Security Notices (USN)

+ [USN-3820-3](https://usn.ubuntu.com/USN-3820-3)
+ Linux kernel (Azure) vulnerabilities
+ 14 November 2018

+ [USN-3820-2](https://usn.ubuntu.com/USN-3820-2)
+ Linux kernel (HWE) vulnerabilities
+ 14 November 2018

+ [USN-3820-1](https://usn.ubuntu.com/USN-3820-1)
+ Linux kernel vulnerabilities
+ 14 November 2018

+ [USN-3819-1](https://usn.ubuntu.com/USN-3819-1)
+ Linux kernel vulnerability
+ 14 November 2018

### Other references

* <https://xenbits.xen.org/xsa/advisory-270.html>
* <https://bugs.chromium.org/p/project-zero/issues/detail?id=1607>
* <https://www.spinics.net/lists/netdev/msg520271.html>
* <https://www.cve.org/CVERecord?id=CVE-2018-15471>
