CVE-2018-13098
published 2018-07-03CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.29%
67.4th percentile
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.18.10-1 (bookworm) | linux 4.18.10-1 (bookworm) |
| linux | linux_kernel | <= 4.17.3 | — |
| linux | linux_kernel | >= 0 < 4.18.10-1 | 4.18.10-1 |
| linux | linux_kernel | >= 0 < 4.18.10-1 | 4.18.10-1 |
| linux | linux_kernel | >= 0 < 4.18.10-1 | 4.18.10-1 |
| linux | linux_kernel | >= 0 < 4.18.10-1 | 4.18.10-1 |
| linux | linux_kernel | >= 0 < 4.15.0-58.64 | 4.15.0-58.64 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvrw-3q4m-69ch: An issue was discovered in fs/f2fs/inode
ghsa_unreviewed·2022-05-14
CVE-2018-13098 [MEDIUM] CWE-125 GHSA-wvrw-3q4m-69ch: An issue was discovered in fs/f2fs/inode
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
OSV
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when moun
OSV
CVE-2018-13098: An issue was discovered in fs/f2fs/inode
osv·2018-07-03·CVSS 5.5
CVE-2018-13098 [MEDIUM] CVE-2018-13098: An issue was discovered in fs/f2fs/inode
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when mounted,
could cause a denial of service (s
Red Hat
kernel: slab out-of-bounds read in fs/f2fs/inode.c
vendor_redhat·2018-06-22·CVSS 5.5
CVE-2018-13098 [MEDIUM] CWE-125 kernel: slab out-of-bounds read in fs/f2fs/inode.c
kernel: slab out-of-bounds read in fs/f2fs/inode.c
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
An issue was discovered in the F2FS filesystem code in the Linux kernel in fs/f2fs/inode.c. A denial of service due to a slab out-of-bounds read can occur for a crafted f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Li
Debian
CVE-2018-13098: linux - An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A...
vendor_debian·2018·CVSS 5.5
CVE-2018-13098 [MEDIUM] CVE-2018-13098: linux - An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A...
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
Scope: local
bookworm: resolved (fixed in 4.18.10-1)
bullseye: resolved (fixed in 4.18.10-1)
forky: resolved (fixed in 4.18.10-1)
sid: resolved (fixed in 4.18.10-1)
trixie: resolved (fixed in 4.18.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c [fedora-all]
bugzilla·2018-07-03·CVSS 5.5
CVE-2018-13098 [MEDIUM] CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c [fedora-all]
CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c
bugzilla·2018-07-03·CVSS 5.5
CVE-2018-13098 [MEDIUM] CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c
CVE-2018-13098 kernel: slab out-of-bounds read in fs/f2fs/inode.c
An issue was discovered in the F2FS filesystem code in the Linux kernel in fs/f2fs/inode.c. A denial of service due to a slab out-of-bounds read can occur for a crafted f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=200173
A suggested upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/chao/linux.git/commit/?h=f2fs-dev&id=346886775c5fa6a541c0148bbecc0554ab9d6dad
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1597795]
---
Note:
An F2FS filesystem is not shipped with any of the Red Hat products.
http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=200173https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=76d56d4ab4f2a9e4f085c7d77172194ddaccf7d2https://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4118-1/http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=200173https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=76d56d4ab4f2a9e4f085c7d77172194ddaccf7d2https://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4118-1/
2018-07-03
Published