UBUNTU-CVE-2018-18690
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-18690
UBUNTU-CVE-2018-18690
Summary:
Details: In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.
References: https://ubuntu.com/security/CVE-2018-18690, https://ubuntu.com/security/notices/USN-3847-1, https://ubuntu.com/security/notices/USN-3847-2, https://ubuntu.com/security/notices/USN-3847-3, https://ubuntu.com/security/notices/USN-3848-1, https://ubuntu.com/security/notices/USN-3848-2, https://ubuntu.com/security/notices/USN-3849-1, https://ubuntu.com/security/notices/USN-3849-2, https://www.cve.org/CVERecord?id=CVE-2018-18690
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
