There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
The product dereferences a pointer that it expects to be valid but is NULL.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://lore.kernel.org/linux-f2fs-devel/20230522124203.3838360-1-chao%40kernel.org/ | patch |
https://www.debian.org/security/2023/dsa-5480 | third party advisory vendor advisory |
https://www.debian.org/security/2023/dsa-5492 | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20230929-0002/ | third party advisory |
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html | third party advisory mailing list |