CVE-2017-18249

Description

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.063

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-3932-1) linux-image-aws_4.4.0.1079.82_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-kvm_4.4.0.1043.43_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-generic_4.4.0.145.153_i386.debLinux
Linux kernel (USN-3932-1) linux-image-generic_4.4.0.145.153_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-virtual_4.4.0.145.153_i386.debLinux
Linux kernel (USN-3932-1) linux-image-virtual_4.4.0.145.153_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-lowlatency_4.4.0.145.153_i386.debLinux
Linux kernel (USN-3932-1) linux-image-lowlatency_4.4.0.145.153_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-1043-kvm_4.4.0-1043.49_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-1079-aws_4.4.0-1079.89_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-145-generic_4.4.0-145.171_i386.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-145-generic_4.4.0-145.171_amd64.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-145-lowlatency_4.4.0-145.171_i386.debLinux
Linux kernel (USN-3932-1) linux-image-4.4.0-145-lowlatency_4.4.0-145.171_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3932-2) linux-image-4.4.0-1040-aws_4.4.0-1040.43_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3932-2) linux-image-4.4.0-144-generic_4.4.0-144.170~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3932-2) linux-image-4.4.0-144-generic_4.4.0-144.170~14.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3932-2) linux-image-4.4.0-144-lowlatency_4.4.0-144.170~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3932-2) linux-image-4.4.0-144-lowlatency_4.4.0-144.170~14.04.1_amd64.debLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-base-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-base-debuginfo-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-debuginfo-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-debugsource-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-azure-devel-4.4.176-4.25.1.x86_64.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-devel-azure-4.4.176-4.25.1.noarch.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-source-azure-4.4.176-4.25.1.noarch.rpmLinux
SUSE-SU-2019:0901-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-syms-azure-4.4.176-4.25.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234