PT-2018-3517 · Linux+2 · Linux Kernel+2

Wen Xu

·

Published

2018-07-26

·

Updated

2019-09-02

·

CVE-2018-14614

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions through 4.17.10
Description: The issue is related to the remove dirty segment() function in the Linux kernel, which is associated with a null pointer dereference. Exploitation of this issue may allow an attacker to cause a denial of service. There is an out-of-bounds access in the remove dirty segment() function in fs/f2fs/segment.c when mounting an f2fs image.
Recommendations: For Linux kernel versions through 4.17.10, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict access to the remove dirty segment() function in fs/f2fs/segment.c to minimize the risk of exploitation. Avoid mounting untrusted f2fs images until the issue is resolved.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2092
ALT-PU-2018-2094
ALT-PU-2019-1433
BDU:2020-03258
CVE-2018-14614
DLA-1715-1
USN-3932-1
USN-3932-2
USN-4094-1
USN-4118-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu