PT-2017-13402 · Linux+3 · Linux Kernel+3

Published

2017-09-14

·

Updated

2018-07-09

·

CVE-2017-14340

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.13.2
Description The issue allows local users to cause a denial of service, resulting in a NULL pointer dereference and OOPS, via vectors related to setting an RHINHERIT flag on a directory. This is due to the XFS IS REALTIME INODE macro in fs/xfs/xfs linux.h not verifying that a filesystem has a realtime device.
Recommendations For Linux kernel versions prior to 4.13.2, update to version 4.13.2 or later to resolve the issue.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2209
ALT-PU-2018-1991
CVE-2017-14340
DLA-1099-1
DSA-3981-1
MGASA-2017-0342
MGASA-2017-0343
MGASA-2017-0344
MGASA-2017-0345
MGASA-2017-0346
MGASA-2017-0347
RHSA-2017:2918
SUSE-SU-2017:2694-1
SUSE-SU-2017:3265-1
SUSE-SU-2018:0040-1
USN-3468-1
USN-3468-2
USN-3468-3
USN-3469-1
USN-3469-2
USN-3470-1
USN-3470-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu