First published: Wed Sep 13 2017(Updated: )
It was found that XFS filesystem code mishandles a user settable inode flag in the Linux kernels prior to 4.14-rc1 which can cause a local denial of service via a kernel panic. External References: <a href="http://seclists.org/oss-sec/2017/q3/436">http://seclists.org/oss-sec/2017/q3/436</a> An upstream patch: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b31ff3cdf540110da4572e3e29bd172087af65cc">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b31ff3cdf540110da4572e3e29bd172087af65cc</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=4.13.1 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.133-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14340 has a severity rating of medium, as it can lead to a local denial of service via a kernel panic.
To fix CVE-2017-14340, update to a Linux kernel version that is 4.14-rc1 or later.
CVE-2017-14340 affects Linux kernel versions up to and including 4.13.1.
Failure to patch CVE-2017-14340 may result in system instability and potential denial of service.
Any user operating an affected version of the Linux kernel could potentially experience a local denial of service due to CVE-2017-14340.