Lucene search

K
cvelistRedhatCVELIST:CVE-2018-1092
HistoryApr 02, 2018 - 3:00 a.m.

CVE-2018-1092

2018-04-0203:00:00
redhat
www.cve.org
1

6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.8%

The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory with a zero i_links_count, which allows attackers to cause a denial of service (ext4_process_freed_data NULL pointer dereference and OOPS) via a crafted ext4 image.

CNA Affected

[
  {
    "product": "Linux kernel through version 4.15",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Linux kernel through version 4.15"
      }
    ]
  }
]