PT-2015-1019 · Linux+4 · Linux Kernel+4
Brian Foster
·
Published
2014-06-09
·
Updated
2024-02-15
·
CVE-2015-0274
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
linux-image-3.13.0
Linux kernel versions prior to 3.15
Description
The issue affects the XFS implementation in the Linux kernel, where an old size value is improperly used during remote attribute replacement. This can be exploited locally to cause a denial of service, resulting in transaction overrun and data corruption, or possibly gain privileges by leveraging XFS filesystem access.
Recommendations
For linux-image-3.13.0, update to a version later than 3.13.0 to mitigate the risk.
For Linux kernel versions prior to 3.15, update to version 3.15 or later to resolve the issue.
As a temporary workaround, consider restricting access to the XFS filesystem to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu