PT-2009-6767 · Opensuse+2 · Opensuse+2

Published

1970-01-01

·

Updated

2018-10-10

·

CVE-2009-4308

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-ps3-debuginfo versions (affected versions not specified) openSUSE kernel-ps3-debugsource versions (affected versions not specified) Linux kernel versions prior to 2.6.32
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. In the Linux kernel, the ext4 decode error function in fs/ext4/super.c allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference) via a crafted read-only filesystem that lacks a journal.
Recommendations For openSUSE kernel-ps3-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For openSUSE kernel-ps3-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Linux kernel versions prior to 2.6.32, update to version 2.6.32 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted read-only filesystems that lack a journal to minimize the risk of exploitation.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05250
BDU:2015-05251
CVE-2009-4308
DSA-2005-1
RHSA-2010:0147
RHSA-2010_0147

Affected Products

Linux Kernel
Red Hat
Opensuse