Lucene search

K
redhatcveRedhat.comRH:CVE-2018-14617
HistoryApr 08, 2020 - 9:16 p.m.

CVE-2018-14617

2020-04-0821:16:52
redhat.com
access.redhat.com
16

0.001 Low

EPSS

Percentile

40.6%

An issue was discovered in the Linux kernel. A NULL pointer dereference and panic in hfsplus_lookup() in the fs/hfsplus/dir.c function can occur when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory.

Mitigation

If the HFS+ filesystem is not in use, this module can be blacklisted and prevented from being loaded. See <https://access.redhat.com/solutions/41278&gt; for instructions on how to blacklist the 'hfsplus.ko' kernel module.