PT-2023-24379 · Unknown+1 · Erofs-Utils+1

Lometsj

·

Published

2023-06-01

·

Updated

2025-01-09

·

CVE-2023-33551

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions erofs-utils version 1.6
Description The issue is related to a Heap Buffer Overflow in the erofsfsck dirent iter function in fsck/main.c. This allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
Recommendations For erofs-utils version 1.6, consider disabling the erofsfsck dirent iter function until a patch is available. Restrict access to crafted erofs filesystem images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-33551
MGASA-2024-0241
OPENSUSE-SU-2024:13318-1

Affected Products

Debian
Erofs-Utils