First published: Thu Jun 28 2018(Updated: )
ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =16.04.4 | |
Linux kernel | =4.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12931 is classified as a medium-severity vulnerability due to its potential to cause denial of service or kernel panics.
To mitigate CVE-2018-12931, you should update to the patched version of the Linux kernel provided by your distribution.
CVE-2018-12931 affects Ubuntu 16.04.4 and Linux Kernel version 4.15.
Exploitation of CVE-2018-12931 could lead to a stack-based out-of-bounds write, resulting in kernel oops or panic.
Currently, the best workaround for CVE-2018-12931 is to avoid using the affected ntfs filesystem until a fix is applied.