Description
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11745 | The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image. |
Ubuntu USN |
USN-3695-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3695-2 | Linux kernel (HWE) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:51:48.616Z
Reserved: 2017-12-04T00:00:00.000Z
Link: CVE-2018-1095
No data.
Status : Modified
Published: 2018-04-02T03:29:00.433
Modified: 2024-11-21T03:59:10.320
Link: CVE-2018-1095
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN