PT-2009-6767 · Opensuse+2 · Opensuse+2
Published
1970-01-01
·
Updated
2018-10-10
·
CVE-2009-4308
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
openSUSE kernel-ps3-debuginfo versions (affected versions not specified)
openSUSE kernel-ps3-debugsource versions (affected versions not specified)
Linux kernel versions prior to 2.6.32
Description
The issue affects the confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. In the Linux kernel, the
ext4 decode error function in fs/ext4/super.c allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference) via a crafted read-only filesystem that lacks a journal.Recommendations
For openSUSE kernel-ps3-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For openSUSE kernel-ps3-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Linux kernel versions prior to 2.6.32, update to version 2.6.32 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted read-only filesystems that lack a journal to minimize the risk of exploitation.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Opensuse