Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g83r-mj94-3hcx

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

EPSS

Процентиль: 28%
0.00097
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 8 лет назад

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

CVSS3: 6.2
redhat
больше 8 лет назад

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

CVSS3: 4.3
nvd
больше 8 лет назад

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

CVSS3: 4.3
debian
больше 8 лет назад

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel th ...

oracle-oval
около 8 лет назад

ELSA-2017-1308: kernel security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 28%
0.00097
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125