Описание
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
A flaw was found in NILFS utilities. An attacker can exploit this vulnerability by supplying a crafted NILFS2 image. This can lead to undefined behavior, oversized shifts, or out-of-memory conditions, ultimately causing a Denial of Service (DoS) by crashing tools such as nilfs-tune and dumpseg.
Отчет
This Moderate impact flaw in NILFS utilities allows a local attacker to trigger a Denial of Service. By supplying a crafted NILFS2 image, an attacker can cause tools like nilfs-tune or dumpseg to crash due to improper validation of superblock fields. This requires user interaction with a malicious file.
Меры по смягчению последствий
To mitigate this issue, avoid processing NILFS2 images from untrusted sources. Restrict the use of NILFS utilities, such as nilfs-tune and dumpseg, to trusted administrators and environments. This reduces the exposure to specially crafted malicious NILFS2 images.
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_va ...
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
EPSS
5.5 Medium
CVSS3