In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Dec 17, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernelUpgrade python3-perfUpgrade kernel-tools-libsUpgrade kernel-headersUpgrade kernel-sourceUpgrade kernel-toolsUpgrade perfUpgrade python-perfUpgrade bpftoolUpgrade kernel-devel | Apr 21, 2020 | Dec 17, 2019 |
| Ubuntu | — | Upgrade linux-hweUpgrade linux-hwe-edge | Nov 19, 2024 | Dec 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub