{"id":"UBUNTU-CVE-2018-12714","details":"An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via crafted perf_event_open and mmap system calls.","modified":"2025-10-24T04:47:05Z","published":"2018-06-24T23:29:00Z","upstream":["CVE-2018-12714"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-12714"},{"type":"REPORT","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=81f9c4e4177d31ced6f52a89bb70e93bfb77ca03"},{"type":"REPORT","url":"https://bugzilla.kernel.org/show_bug.cgi?id=200019"},{"type":"REPORT","url":"https://github.com/lcytxw/bug_repro/tree/master/bug_200019"},{"type":"REPORT","url":"https://github.com/torvalds/linux/commit/81f9c4e4177d31ced6f52a89bb70e93bfb77ca03"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-12714"}],"affected":[{"package":{"name":"linux-azure-edge","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/linux-azure-edge@5.0.0-1012.12~18.04.2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.18.0-1006.6~18.04.1","4.18.0-1007.7~18.04.1","4.18.0-1008.8~18.04.1","5.0.0-1012.12~18.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"linux-azure-edge-cloud-tools-5.0.0-1012","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-azure-edge-tools-5.0.0-1012","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_version":"5.0.0-1012.12~18.04.2","binary_name":"linux-azure-headers-5.0.0-1012"},{"binary_name":"linux-buildinfo-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-cloud-tools-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-headers-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-image-unsigned-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-modules-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_name":"linux-modules-extra-5.0.0-1012-azure","binary_version":"5.0.0-1012.12~18.04.2"},{"binary_version":"5.0.0-1012.12~18.04.2","binary_name":"linux-tools-5.0.0-1012-azure"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12714.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}