Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1095

Опубликовано: 02 апр. 2018
Источник: debian
EPSS Низкий

Описание

The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.16.5-1package
linuxnot-affectedstretchpackage
linuxnot-affectedjessiepackage
linuxnot-affectedwheezypackage

Примечания

  • https://bugzilla.kernel.org/show_bug.cgi?id=199185

EPSS

Процентиль: 36%
0.00153
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

CVSS3: 5.2
redhat
почти 8 лет назад

The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

CVSS3: 5.5
nvd
почти 8 лет назад

The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

CVSS3: 5.5
github
больше 3 лет назад

The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

CVSS3: 5.5
fstec
почти 8 лет назад

Уязвимость функции ext4_xattr_check_entries ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00153
Низкий