PT-2018-6733 · Linux+3 · Linux Kernel+3

Published

2017-12-08

·

Updated

2020-11-24

·

CVE-2017-18204

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.14.2
Description: The issue allows local users to cause a denial of service (deadlock) via DIO requests. This is due to a problem in the ocfs2 setattr function in fs/ocfs2/file.c.
Recommendations: For Linux kernel versions prior to 4.14.2, update to version 4.14.2 or later to resolve the issue. As a temporary workaround, consider restricting DIO requests to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2017-2771
ALT-PU-2018-1991
CVE-2017-18204
SUSE-SU-2018:0834-1
SUSE-SU-2018:0848-1
SUSE-SU-2020:3501-1
SUSE-SU-2020:3503-1
USN-3617-1
USN-3617-2
USN-3617-3
USN-3619-1
USN-3619-2
USN-3655-1
USN-3655-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu