CVE-2022-1304: High severity e2fsprogs vulnerability
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Other sources
An out-of-bounds read/write vulnerability was found in e2fsprogs which can lead to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem. The issue occurs in ext2fsextentdelete() in lib/ext2fs/extent.c when path->left is equal to -1, resulting in a call to memmove() with invalid arguments.
Reference: https://bugzilla.redhat.com/showbug.cgi?id=2068113
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1304?
CVE-2022-1304 is an out-of-bounds read/write vulnerability found in e2fsprogs 1.46.5.
What is the severity of CVE-2022-1304?
CVE-2022-1304 has a severity rating of 7.8 (high).
How does CVE-2022-1304 affect e2fsprogs?
CVE-2022-1304 affects e2fsprogs 1.46.5, leading to a segmentation fault and possibly arbitrary code execution.
Which software versions are affected by CVE-2022-1304?
CVE-2022-1304 affects e2fsprogs 1.46.5, Redhat Enterprise Linux 6.0, 7.0, 8.0, and Fedoraproject Fedora 35.
How can CVE-2022-1304 be fixed?
Please update e2fsprogs to version 1.46.6 or apply the necessary patches provided by the vendor.