ZeroHour

CVE-2017-18257

CVSS 3.0
5.5 medium
EPSS
<1%p32
Published
()
Modified
Description

The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

Vendors
linuxdebian
Products
linux kernel, debian linux
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.