PT-2018-3521 · Linux+2 · Linux Kernel+2

Po-Ning Tseng

+1

·

Publicado

2018-07-26

·

Atualizado

2020-06-10

·

CVE-2018-14610

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.17.11
Description: The issue is related to out-of-bounds access in the write extent buffer() function when mounting and operating a crafted btrfs image. This occurs due to a lack of verification that each block group has a corresponding chunk at mount time, within btrfs read block groups in fs/btrfs/extent-tree.c. The vulnerability can be exploited to cause a denial of service.
Recommendations: For Linux kernel versions prior to 4.17.11, update to version 4.17.11 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted btrfs images to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2092
ALT-PU-2018-2094
ALT-PU-2019-1433
BDU:2020-03262
CVE-2018-14610
DLA-1715-1
DLA-2241-1
DLA-2241-2
USN-3932-1
USN-3932-2
USN-4094-1
USN-4118-1

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu