Lucene search

K
redhatcveRedhat.comRH:CVE-2022-3621
HistoryNov 08, 2022 - 3:55 a.m.

CVE-2022-3621

2022-11-0803:55:56
redhat.com
access.redhat.com
186
nilfs2
file system
denial of service
linux kernel
metadata files
null pointer
disk corruption

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

55.5%

A flaw was found in the NILFS2 file system implementation in the Linux kernel. If the i_mode field in inode of the metadata files is corrupted on the disk, it can cause the initialization of the bmap structure not being called, resulting in a NULL pointer dereference at nilfs_bmap_lookup_at_level. A user permitted to mount arbitrary file system images could use this flaw to cause a denial of service.

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

55.5%