Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 5.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernel | Aug 28, 2019 | Jul 16, 2018 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Jul 16, 2018 |
| Redhat_linux | — | Upgrade kernelNo solution exists | Jan 30, 2019 | Jul 16, 2018 |
| Ubuntu | — | Upgrade linux-image-awsUpgrade linux-image-4.15.0-1020-awsUpgrade linux-image-4.15.0-1018-gcpUpgrade linux-image-generic-lpae-hwe-16.04Upgrade linux-image-raspi2Upgrade linux-image-4.15.0-33-snapdragonUpgrade linux-image-gcpUpgrade linux-image-azure-edgeUpgrade linux-image-4.15.0-1021-raspi2Upgrade linux-image-4.15.0-33-lowlatencyUpgrade linux-image-4.15.0-1017-oemUpgrade linux-image-kvmUpgrade linux-image-snapdragonUpgrade linux-image-generic-hwe-16.04Upgrade linux-image-lowlatency-hwe-16.04Upgrade linux-image-lowlatencyUpgrade linux-image-generic-lpaeUpgrade linux-image-4.15.0-1020-kvmUpgrade linux-image-oemUpgrade linux-image-4.15.0-33-generic-lpaeUpgrade linux-image-4.15.0-1022-azureUpgrade linux-image-azureUpgrade linux-image-genericUpgrade linux-image-4.15.0-33-genericUpgrade linux-image-gke | Aug 31, 2018 | Jul 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub