Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27568
HistoryOct 14, 2020 - 1:07 a.m.

Arbitrary Code Execution

2020-10-1401:07:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
arbitrary code execution
mounting malicious image
syncfs system call
software vulnerability

EPSS

0.001

Percentile

46.3%

kernel is vulnerable to arbitrary code execution. A user-after-free occurs in try_merge_free_space in fs/btrfs/free-space-cache.c when mounting malicious btrfs filesystem image and subsequently making a syncfs system call. This could potentially lead to arbitrary code execution on the OS.