First published: Fri Jul 27 2018(Updated: )
An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=4.17.10 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.133-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14616 has a medium severity rating due to the potential for NULL pointer dereference vulnerabilities in the Linux kernel.
To fix CVE-2018-14616, upgrade your Linux kernel to a version that is 5.10.223-1 or higher, or 6.1.123-1 or higher.
CVE-2018-14616 affects all Linux kernel versions up to 4.17.10 inclusive.
The vulnerability in CVE-2018-14616 primarily involves the fscrypt_do_page_crypto() function in the fs/crypto/crypto.c file.
Systems operating on corrupted f2fs images in affected Linux kernels are at risk from CVE-2018-14616.