Description
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-3752-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3752-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3752-3 | Linux kernel (Azure, GCP, OEM) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:10:13.990Z
Reserved: 2018-05-24T00:00:00.000Z
Link: CVE-2018-11412
No data.
Status : Modified
Published: 2018-05-24T18:29:00.190
Modified: 2024-11-21T03:43:18.820
Link: CVE-2018-11412
OpenCVE Enrichment
No data.
Ubuntu USN