CVE-2018-1094 PUBLISHED

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image.

EPSS 0.29% · 51.7th percentile

Risk Scores

EPSS Score
0.29%
51.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-oem4.15.0-1008.11, 0, 4.15.0-1002.3
Ubuntu:18.04:LTSlinux-aws4.15.0-1006.6, 4.15.0-1007.7, 4.15.0-1009.9
Ubuntu:18.04:LTSlinux-raspi24.15.0-1006.7, 0, 4.13.0-1005.5
Ubuntu:18.04:LTSlinux4.13.0-16.19, 4.15.0-23.25, 4.15.0-22.24
Ubuntu:16.04:LTSlinux-azure4.11.0-1015.15, 4.11.0-1014.14, 4.11.0-1013.13
Ubuntu:18.04:LTSlinux-kvm4.15.0-1010.10, 0, 4.15.0-1002.2
Ubuntu:16.04:LTSlinux-hwe4.13.0-32.35~16.04.1, 4.13.0-36.40~16.04.1, 4.13.0-37.42~16.04.1
Ubuntu:18.04:LTSlinux-gcp4.15.0-1006.6, 0, 4.15.0-1001.1
Ubuntu:18.04:LTSlinux-azure0, 4.15.0-1009.9, 4.15.0-1013.13
Ubuntu:16.04:LTSlinux-gcp4.13.0-1017.21, 0, 4.13.0-1015.19

Timeline

References

Open in Interactive Console →