An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/xfs/xfs_buf_item_recover.c?h=v6.4-rc1&id=22ed903eee23a5b174e240f1cdfa9acf393a5210 | patch vendor advisory mailing list |
https://syzkaller.appspot.com/bug?extid=7e9494b8b399902e994e | mailing list third party advisory exploit |
https://security.netapp.com/advisory/ntap-20230622-0010/ | third party advisory |
https://www.debian.org/security/2023/dsa-5448 | third party advisory vendor advisory |
https://www.debian.org/security/2023/dsa-5480 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html | third party advisory mailing list |