CVE-2018-13095
Description
An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.17.3. A denial of service (memory corruption and BUG) can occur for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit in the inode fork.
Risk Information
Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.301
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update bpftool-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-abi-whitelists-3.10.0-1062.el7.noarch.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-debug-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-debug-devel-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-devel-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-doc-3.10.0-1062.el7.noarch.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-headers-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-tools-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-tools-libs-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update kernel-tools-libs-devel-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update perf-3.10.0-1062.el7.x86_64.rpm | Linux |
| (RHSA-2019:2029) kernel security, bug fix, and enhancement update python-perf-3.10.0-1062.el7.x86_64.rpm | Linux |
| Linux kernel (USN-4904-1) linux-image-aws_4.4.0.1126.131_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-kvm_4.4.0.1091.89_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-generic_4.4.0.208.214_i386.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-generic_4.4.0.208.214_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-virtual_4.4.0.208.214_i386.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-virtual_4.4.0.208.214_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-lowlatency_4.4.0.208.214_i386.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-lowlatency_4.4.0.208.214_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-1091-kvm_4.4.0-1091.100_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-1126-aws_4.4.0-1126.140_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-208-generic_4.4.0-208.240_i386.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-208-generic_4.4.0-208.240_amd64.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-208-lowlatency_4.4.0-208.240_i386.deb | Linux |
| Linux kernel (USN-4904-1) linux-image-4.4.0-208-lowlatency_4.4.0-208.240_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-gcp_4.15.0.1097.98_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-gke_4.15.0.1097.98_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-kvm_4.15.0.1089.85_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-azure_4.15.0.1112.103_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-oracle_4.15.0.1069.57_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-aws-hwe_4.15.0.1098.91_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-generic_4.15.0.141.128_i386.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-generic_4.15.0.141.128_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-virtual_4.15.0.141.128_i386.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-virtual_4.15.0.141.128_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-dell300x_4.15.0.1016.18_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-lowlatency_4.15.0.141.128_i386.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-lowlatency_4.15.0.141.128_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-aws-lts-18.04_4.15.0.1098.101_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-gcp-lts-18.04_4.15.0.1097.115_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1089-kvm_4.15.0-1089.91_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1097-gcp_4.15.0-1097.110_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1097-gcp_4.15.0-1097.110~16.04.1_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1098-aws_4.15.0-1098.105_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1098-aws_4.15.0-1098.105~16.04.1_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-azure-lts-18.04_4.15.0.1112.85_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-oracle-lts-18.04_4.15.0.1069.79_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1112-azure_4.15.0-1112.125_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1112-azure_4.15.0-1112.124~16.04.1_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1069-oracle_4.15.0-1069.77_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1069-oracle_4.15.0-1069.77~16.04.1_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-141-generic_4.15.0-141.145_i386.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-141-generic_4.15.0-141.145_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-1016-dell300x_4.15.0-1016.20_amd64.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-141-lowlatency_4.15.0-141.145_i386.deb | Linux |
| Linux kernel (USN-4907-1) linux-image-4.15.0-141-lowlatency_4.15.0-141.145_amd64.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234