PT-2018-2899 · Linux+3 · Linux Kernel+3

Wen Xu

·

Published

2018-07-26

·

Updated

2019-09-02

·

CVE-2018-14617

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.17.11
Description The issue is related to a NULL pointer dereference and panic in the hfsplus lookup() function in fs/hfsplus/dir.c when opening a file in an hfs+ filesystem with malformed catalog data, mounted read-only without a metadata directory. This can lead to a denial of service.
Recommendations For Linux kernel versions prior to 4.17.11, update to version 4.17.11 or later to resolve the issue. As a temporary workaround, consider avoiding the use of hfs+ filesystems with malformed catalog data, or ensure they are mounted with a metadata directory when possible.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2092
ALT-PU-2018-2094
ALT-PU-2019-1433
BDU:2019-02512
CVE-2018-14617
DLA-1529-1
DLA-1531-1
DSA-4308-1
OPENSUSE-SU-2018_3071-1
OPENSUSE-SU-2018_3202-1
SUSE-SU-2018:2879-1
SUSE-SU-2018:2908-1
SUSE-SU-2018:2908-2
SUSE-SU-2018:2980-1
SUSE-SU-2018:2981-1
SUSE-SU-2018:3003-1
SUSE-SU-2018:3004-1
SUSE-SU-2018:3083-1
SUSE-SU-2018:3084-1
SUSE-SU-2018:3088-1
SUSE-SU-2018:3618-1
SUSE-SU-2018:3659-1
SUSE-SU-2018:3961-1
SUSE-SU-2019:0095-1
USN-3821-1
USN-3821-2
USN-4094-1
USN-4118-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu