kernel: TLB flush happens too late on mremap
Published Oct 30, 2018
7.8
HIGHCVSS 3.0
EPSS 1.06%
Description
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19.
Affected products
No data.
Configuration 1
- ≥ 3.2 · < 4.9.135
- ≥ 4.9.136 · < 4.14.78
- ≥ 4.14.79 · < 4.18.16
- ≥ 4.18.17 · < 4.19
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 3
- 8.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.el7
Fixed · RHSA-2019:2029
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.7.1.el7a
Fixed · RHSA-2019:0831
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.rt56.1022.el7
Fixed · RHSA-2019:2043
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.62.1.el7
Fixed · RHSA-2020:0103
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
kernel-0:3.10.0-693.62.1.el7
Fixed · RHSA-2020:0103
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
kernel-0:3.10.0-693.62.1.el7
Fixed · RHSA-2020:0103
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.46.1.el7
Fixed · RHSA-2020:0036
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.43.1.el7
Fixed · RHSA-2020:0179
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.62.1.rt56.659.el6rt
Fixed · RHSA-2020:0100
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.43.1.el7
Fixed · RHSA-2020:0179
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.el7 | Fixed | RHSA-2019:2029 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.7.1.el7a | Fixed | RHSA-2019:0831 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.rt56.1022.el7 | Fixed | RHSA-2019:2043 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.62.1.el7 | Fixed | RHSA-2020:0103 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | kernel-0:3.10.0-693.62.1.el7 | Fixed | RHSA-2020:0103 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | kernel-0:3.10.0-693.62.1.el7 | Fixed | RHSA-2020:0103 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.46.1.el7 | Fixed | RHSA-2020:0036 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.43.1.el7 | Fixed | RHSA-2020:0179 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.62.1.rt56.659.el6rt | Fixed | RHSA-2020:0100 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.43.1.el7 | Fixed | RHSA-2020:0179 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.06% (0.01061) | 63.38th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.07% (0.01070) | 60.33th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.29% (0.00290) | 49.44th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.49% (0.01491) | 69.26th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.06% (0.00063) | 16.89th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.11% (0.00111) | 46.00th | v3 (v2023.03.01) |
| Oct 24, 2023 | 0.11% (0.00111) | 43.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00093) | 38.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.62% (0.05624) | 80.44th | v1 |
| Jan 6, 2022 | 5.62% (0.05624) | 80.25th | v1 |
| Sep 1, 2021 | 5.62% (0.05624) | 88.97th | v1 |
| Apr 14, 2021 | 5.62% (0.05624) | 0.00th | v1 |
References (31)
- http://packetstormsecurity.com/files/150001/Linux-mremap-TLB-Flush-Too-Late.html x_refsource_MISCPatchThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2018/10/29/5 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/105761 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/106503 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0831 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2029 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2043 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0036 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0100 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0103 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0179 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-18281 Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1695 x_refsource_MISCExploitPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1645121 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.78 x_refsource_CONFIRMPatchVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.16 x_refsource_CONFIRMPatchVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.135 x_refsource_CONFIRMPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=eb66ae030829605d61fbef1909ce310e29f78821 x_refsource_CONFIRMPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-18281
- https://usn.ubuntu.com/3832-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3835-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3871-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3871-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3871-4/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3871-5/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3880-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3880-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-18281
Change history (0)
No recorded changes yet.