Vulnerability CVE-2017-18257


Published: 2018-04-04

Description:
The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

Type:

CWE-190

(Integer Overflow or Wraparound)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Linux -> Linux kernel 
Debian -> Debian linux 

 References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b86e33075ed1909d8002745b56ecf73b833db143
https://github.com/torvalds/linux/commit/b86e33075ed1909d8002745b56ecf73b833db143
https://usn.ubuntu.com/3696-1/
https://usn.ubuntu.com/3696-2/
https://www.debian.org/security/2018/dsa-4188

Copyright 2024, cxsecurity.com

 

Back to Top