{"id":"CVE-2018-10902","title":"It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() han…","summary":"It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() han…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-415"],"vendor":"debian","product":"debian_linux","affected":["debian_linux = 8.0","debian_linux = 9.0","ubuntu_linux = 12.04","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","linux_kernel","enterprise_linux_desktop = 6.0","enterprise_linux_desktop = 7.0","enterprise_linux_server = 6.0","enterprise_linux_server = 7.0","enterprise_linux_workstation = 6.0","enterprise_linux_workstation = 7.0"],"published":"2018-08-21","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-10902","references":[{"url":"http://www.securityfocus.com/bid/105119","label":"secalert@redhat.com"},{"url":"http://www.securitytracker.com/id/1041529","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2018:3083","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2018:3096","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2019:0415","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2019:0641","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2019:3217","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2019:3967","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10902","label":"secalert@redhat.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=39675f7a7c7e7702f7d5341f1e0d01db746543a0","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3776-1/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3776-2/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3847-1/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3847-2/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3847-3/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3849-1/","label":"secalert@redhat.com"},{"url":"https://usn.ubuntu.com/3849-2/","label":"secalert@redhat.com"},{"url":"https://www.debian.org/security/2018/dsa-4308","label":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/105119","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1041529","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2018:3083","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2018:3096","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:0415","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:0641","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3217","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3967","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10902","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=39675f7a7c7e7702f7d5341f1e0d01db746543a0","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3776-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3776-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3847-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3847-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3847-3/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3849-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3849-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2018/dsa-4308","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00523,"epssPercentile":0.43177,"ingestedAt":"2026-07-07T15:38:35.702Z","slug":"CVE-2018-10902","body":"## Overview\n\nIt was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.\n\n## Affected\n\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n- `ubuntu_linux = 12.04`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `linux_kernel`\n- `enterprise_linux_desktop = 6.0`\n- `enterprise_linux_desktop = 7.0`\n- `enterprise_linux_server = 6.0`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_workstation = 6.0`\n- `enterprise_linux_workstation = 7.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}