First published: Tue Jul 03 2018(Updated: )
An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <=4.17.3 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
redhat/kernel | <4.18 | 4.18 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.106-3 6.1.112-1 6.11.4-1 6.11.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-13094 is low.
CVE-2018-13094 affects Linux kernel versions up to 4.17.3.
Software packages affected by CVE-2018-13094 include linux-flo, linux-aws, linux-azure, linux-azure-edge, linux, and more. Please refer to the CVE details for a complete list.
Yes, the fix for CVE-2018-13094 is available in Linux kernel versions 4.18 and higher.
You can find more information about CVE-2018-13094 in the references provided: https://bugzilla.kernel.org/show_bug.cgi?id=199969, https://git.kernel.org/pub/scm/fs/xfs/xfs-linux.git/commit/?h=for-next&id=bb3d48dcf86a97dc25fe9fc2c11938e19cb4399a, https://github.com/torvalds/linux/commit/bb3d48dcf86a97dc25fe9fc2c11938e19cb4399a