ZeroHour

CVE-2018-18690

PoC
CVSS 3.0
5.5 medium
EPSS
<1%p50
Published
()
Modified
Description

In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.

Vendors
linuxcanonicaldebian
Products
linux kernel, ubuntu linux, debian linux
Weakness
CWE-754
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.