Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kanda Motohiro

#46143of 53,635
5.5Total CVSS
Vulnerabilities · 1
PT-2018-2685
5.5
2018-04-17
Linux · Linux Kernel · CVE-2018-18690
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 4.17 **Description** The issue is related to the xfs attr shortform addname function in the XFS filesystem implementation, which mishandles ATTR REPLACE operations when converting an attribute from short to long form. This can be exploited by a local attacker who can set attributes on an xfs filesystem, potentially making the filesystem non-operational until the next mount. The exploitation of this issue may allow an attacker to cause a denial of service. **Recommendations** For Linux kernel versions prior to 4.17, consider updating to version 4.17 or later to resolve the issue. As a temporary workaround, restrict access to setting attributes on xfs filesystems to minimize the risk of exploitation.