Vulnerability identifier: #VU104981
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-125
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the orangefs_debug_write() function in fs/orangefs/orangefs-debugfs.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/1c5244299241cf49d8ae7b5054e299cc8faa4e09
https://git.kernel.org/stable/c/1da2697307dad281dd690a19441b5ca4af92d786
https://git.kernel.org/stable/c/2b84a231910cef2e0a16d29294afabfb69112087
https://git.kernel.org/stable/c/897f496b946fdcfab5983c983e4b513ab6682364
https://git.kernel.org/stable/c/f7c848431632598ff9bce57a659db6af60d75b39
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.