CVE-2018-13097 PUBLISHED

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).

EPSS 0.22% · 44.0th percentile

Risk Scores

EPSS Score
0.22%
44.0th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1032.34, 0, 4.15.0-1030.32
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:18.04:LTSlinux-oracle4.15.0-1007.9, 4.15.0-1008.10, 4.15.0-1011.13
Ubuntu:16.04:LTSlinux-hwe4.13.0-26.29~16.04.2, 4.13.0-31.34~16.04.1, 4.13.0-32.35~16.04.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1072.82, 0, 4.4.0-1001.10
Ubuntu:20.04:LTSlinux-gke5.4.0-1057.60, 5.4.0-1080.86, 5.4.0-1081.87
Ubuntu:22.04:LTSlinux-riscv5.15.0-1026.30, 5.15.0-1027.31, 5.15.0-1028.32
Ubuntu:16.04:LTSlinux4.4.0-97.120, 4.4.0-127.153, 4.4.0-124.148
Ubuntu:18.04:LTSlinux-raspi24.15.0-1009.10, 4.15.0-1041.44, 4.15.0-1040.43
Ubuntu:20.04:LTSlinux-riscv5.4.0-40.45, 0, 5.4.0-24.28
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1007.8, 5.3.0-1014.16
Ubuntu:18.04:LTSlinux-hwe4.18.0-17.18~18.04.1, 4.18.0-16.17~18.04.1, 0
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1044.46~16.04.1, 0, 4.15.0-1030.31~16.04.1
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1055.59, 0, 4.4.0-1077.82
Ubuntu:Pro:14.04:LTSlinux3.13.0-202.253, 3.13.0-201.252, 3.13.0-200.251
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1023.24~14.04.1, 4.15.0-1030.31~14.04.1, 4.15.0-1055.60~14.04.1
Ubuntu:18.04:LTSlinux4.15.0-23.25, 4.15.0-22.24, 4.15.0-20.21
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35

…and 19 more

Timeline

References

Open in Interactive Console →