The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Oct 13, 2014 |
| Ubuntu | — | Upgrade linux-image-3.13.0-30-genericUpgrade linux-image-3.11.0-23-generic-lpaeUpgrade linux-image-3.13.0-27-powerpc-e500mcUpgrade linux-image-3.13.0-27-powerpc64-smpUpgrade linux-image-3.13.0-30-generic-lpaeUpgrade linux-image-3.13.0-27-powerpc64-embUpgrade linux-image-3.13.0-27-generic-lpaeUpgrade linux-image-3.13.0-27-powerpc-smpUpgrade linux-image-3.13.0-27-powerpc-e500Upgrade linux-image-3.13.0-27-genericUpgrade linux-image-3.11.0-23-genericUpgrade linux-image-3.13.0-27-lowlatency | Nov 8, 2024 | Oct 13, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub