The srdoioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11506.json"
[
{
"events": [
{
"introduced": "4.11"
},
{
"fixed": "4.14.45"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.16.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]