Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp43-cjr7-6449

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

Ссылки

EPSS

Процентиль: 37%
0.00155
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 10 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

redhat
больше 10 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

nvd
больше 10 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

debian
больше 10 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the ...

oracle-oval
около 10 лет назад

ELSA-2015-3034: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 37%
0.00155
Низкий

Дефекты

CWE-20