SB2018071812 - Out-of-bounds read in Linux kernel
Published: July 18, 2018 Updated: June 1, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2018-10877)
The vulnerability allows a local privileged user to execute arbitrary code.
Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.
Remediation
Install update from vendor's website.