PT-2018-3517 · Linux+2 · Linux Kernel+2
Wen Xu
·
Publicado
2018-07-26
·
Atualizado
2019-09-02
·
CVE-2018-14614
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions through 4.17.10
Description:
The issue is related to the
remove dirty segment() function in the Linux kernel, which is associated with a null pointer dereference. Exploitation of this issue may allow an attacker to cause a denial of service. There is an out-of-bounds access in the remove dirty segment() function in fs/f2fs/segment.c when mounting an f2fs image.Recommendations:
For Linux kernel versions through 4.17.10, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict access to the
remove dirty segment() function in fs/f2fs/segment.c to minimize the risk of exploitation. Avoid mounting untrusted f2fs images until the issue is resolved.Correção
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu