First published: Thu Jun 28 2018(Updated: )
ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | =4.15 | |
Ubuntu Linux | =16.04.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12930 is considered to have a high severity due to the potential for denial of service and other unspecified impacts.
To fix CVE-2018-12930, it is recommended to update the Linux kernel to a version beyond 4.15.0, as later versions contain patches addressing this vulnerability.
CVE-2018-12930 affects the Linux kernel version 4.15.0 and Ubuntu Linux version 16.04.4.
CVE-2018-12930 is a stack-based out-of-bounds write vulnerability that can be exploited through a crafted ntfs filesystem.
While CVE-2018-12930 primarily causes a denial of service, it could potentially be used for further exploitation under certain conditions.