PT-2018-3520 · Linux+2 · Linux Kernel+2
Po-Ning Tseng
+1
·
Publicado
2018-07-26
·
Atualizado
2020-06-10
·
CVE-2018-14611
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 4.17.10
Description:
The issue is related to a use-after-free error in the
try merge free space() function of the Linux kernel, specifically when mounting a crafted btrfs image. This occurs due to a lack of chunk type flag checks in btrfs check chunk valid in fs/btrfs/volumes.c. Exploitation of this issue may allow an attacker to cause a denial of service.Recommendations:
For Linux kernel versions prior to 4.17.10, update to version 4.17.10 or later to resolve the issue. As a temporary workaround, consider restricting the mounting of btrfs images from untrusted sources to minimize the risk of exploitation.
Exploit
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu