PT-2017-13402 · Linux+3 · Linux Kernel+3

Publicado

2017-09-14

·

Atualizado

2018-07-09

·

CVE-2017-14340

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.13.2
Description The issue allows local users to cause a denial of service, resulting in a NULL pointer dereference and OOPS, via vectors related to setting an RHINHERIT flag on a directory. This is due to the XFS IS REALTIME INODE macro in fs/xfs/xfs linux.h not verifying that a filesystem has a realtime device.
Recommendations For Linux kernel versions prior to 4.13.2, update to version 4.13.2 or later to resolve the issue.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2209
ALT-PU-2018-1991
CVE-2017-14340
DLA-1099-1
DSA-3981-1
MGASA-2017-0342
MGASA-2017-0343
MGASA-2017-0344
MGASA-2017-0345
MGASA-2017-0346
MGASA-2017-0347
RHSA-2017:2918
SUSE-SU-2017:2694-1
SUSE-SU-2017:3265-1
SUSE-SU-2018:0040-1
USN-3468-1
USN-3468-2
USN-3468-3
USN-3469-1
USN-3469-2
USN-3470-1
USN-3470-2

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu