Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 14.7%; technical severity is CVSS 7.8.
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Who should care
- Teams operating Ubuntu Linux, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager +26 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager +26 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-190
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 14.04); F5 Big-ip Access Policy Manager (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Advanced Firewall Manager (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Analytics (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Application Acceleration Manager (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Application Security Manager (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Domain Name System (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1); F5 Big-ip Edge Gateway (Start Including 11.2.1, End Excluding 11.6.4 | Start Including 12.1.0, End Excluding 12.1.5 | Start Including 13.0.0, End Excluding 13.1.1.5 | Start Including 14.0.0, End Excluding 14.0.1.1)
- Fixed versions
- F5 Big-ip Access Policy Manager (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Advanced Firewall Manager (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Analytics (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Application Acceleration Manager (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Application Security Manager (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Domain Name System (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Edge Gateway (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6); F5 Big-ip Fraud Protection Service (Fixed from 11.6.4, 12.1.5, 13.1.1.5, 14.0.1.1, 14.1.0.6)
- Published
- 25 September 2018
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 14.7%
- Signal calculated at 71
External references
- Red Hat Third-party advisory RHSA-2018:2748
- Red Hat Third-party advisory RHSA-2018:2763
- Red Hat Third-party advisory RHSA-2018:2846
- Red Hat Third-party advisory RHSA-2018:2924
- Red Hat Third-party advisory RHSA-2018:2925
- Red Hat Third-party advisory RHSA-2018:2933
- Red Hat Third-party advisory RHSA-2018:3540
- Red Hat Third-party advisory RHSA-2018:3586
- Red Hat Third-party advisory RHSA-2018:3590
- Red Hat Third-party advisory RHSA-2018:3591
- Red Hat Third-party advisory RHSA-2018:3643
- Red Hat Third-party advisory CVE-2018-14634