Vulnerability identifier: #VU98913
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-125
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the nilfs_btree_check_delete() function in fs/nilfs2/btree.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/d20674f31626e0596ae4c1d9401dfb6739b81b58
https://git.kernel.org/stable/c/c4f8554996e8ada3be872dfb8f60e93bcf15fb27
https://git.kernel.org/stable/c/a8abfda768b9f33630cfbc4af6c4214f1e5681b0
https://git.kernel.org/stable/c/257f9e5185eb6de83377caea686c306e22e871f2
https://git.kernel.org/stable/c/a33e967b681e088a125b979975c93e3453e686cd
https://git.kernel.org/stable/c/c4cbcc64bb31e67e02940ce060cc77f7180564cf
https://git.kernel.org/stable/c/f9c96351aa6718b42a9f42eaf7adce0356bdb5e8
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.