cbcvebase.
CVE-2022-1304
published 2022-04-14

CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.38%
69.3th percentile
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

Affected

14 ranges
VendorProductVersion rangeFixed in
citrixcitrix_hypervisor
citrixxenserver
debiane2fsprogs< e2fsprogs 1.46.6~rc1-1 (bookworm)e2fsprogs 1.46.6~rc1-1 (bookworm)
e2fsprogs_projecte2fsprogs
e2fsprogs_projecte2fsprogs
e2fsprogs_projecte2fsprogs>= 0 < 1.46.2-2+deb11u11.46.2-2+deb11u1
e2fsprogs_projecte2fsprogs>= 0 < 1.46.6~rc1-11.46.6~rc1-1
e2fsprogs_projecte2fsprogs>= 0 < 1.46.6~rc1-11.46.6~rc1-1
e2fsprogs_projecte2fsprogs>= 0 < 1.46.6~rc1-11.46.6~rc1-1
fedoraprojectfedora
msrccbl2_e2fsprogs_1.46.5-3_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.