Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xq2v-cc3g-cmw3

Опубликовано: 23 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.

Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

ubuntu
9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Filesystem bugs due to corrupt images are not considered a CVE for any filesystem that is only mountable by CAP_SYS_ADMIN in the initial user namespace. That includes delegated mounting.

CVSS3: 5.5
redhat
9 месяцев назад

[REJECTED CVE] Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.

nvd
9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Filesystem bugs due to corrupt images are not considered a CVE for any filesystem that is only mountable by CAP_SYS_ADMIN in the initial user namespace. That includes delegated mounting.

CVSS3: 7.8
fstec
11 месяцев назад

Уязвимость драйвера файловой системы HFS ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3

Дефекты

CWE-787