Out-of-bounds write in E2fsprogs - CVE-2022-1304
Published: June 8, 2022 / Updated: February 3, 2023
Vulnerability identifier: #VU64075
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1304
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A local attacker can use a specially crafted filesystem, trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
E2fsprogs
Oracle Linux
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat CodeReady Linux Builder for IBM z Systems
Brocade Fabric OS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Anolis OS
IBM Cloud Pak for Watson AIOps
cflinuxfs3
ObjectScale
Cloud Pak for Network Automation
OpenManage Network Integration (OMNI)
EMC ECS
Enterprise SONiC
IBM supplied MQ Advanced container images
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
Submariner
NetObserv Operator
Migration Toolkit for Runtimes
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle Communications Cloud Native Core Network Exposure Function
Netcool Operations Insight
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
Red Hat OpenShift Serverless
OpenShift sandboxed containers
OpenShift Service Mesh
Citrix Hypervisor
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
SmartFabric Storage Software
SCALANCE S615
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
e2fsprogs (Red Hat package)
libext2fs2-debuginfo
e2fsprogs-debuginfo-32bit
libcom_err2-debuginfo
libcom_err2-debuginfo-32bit
libcom_err2-32bit
libcom_err2
e2fsprogs-debugsource
e2fsprogs-debuginfo
e2fsprogs
libext2fs2
e2fsprogs-devel
libcom_err-devel
libext2fs-devel
e2fsprogs-32bit-debuginfo
libext2fs-devel-static
libcom_err-devel-static
libcom_err2-32bit-debuginfo
libext2fs-devel-32bit
libext2fs2-32bit
libext2fs2-32bit-debuginfo
libcom_err-devel-32bit
e2fsprogs (Ubuntu package)
e2fsck-static (Ubuntu package)
fuse2fs (Ubuntu package)
e2fslibs (Ubuntu package)
e2fsprogs-help
sys-fs/e2fsprogs
libcom_err
e2scrub
e2fsprogs-static
e2fsprogs-libs
libss-devel
libss
Dell EMC NetWorker vProxy
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Voice Gateway
Cloud Pak for Security (CP4S)
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
Oracle Linux
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat CodeReady Linux Builder for IBM z Systems
Brocade Fabric OS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Anolis OS
IBM Cloud Pak for Watson AIOps
cflinuxfs3
ObjectScale
Cloud Pak for Network Automation
OpenManage Network Integration (OMNI)
EMC ECS
Enterprise SONiC
IBM supplied MQ Advanced container images
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
Submariner
NetObserv Operator
Migration Toolkit for Runtimes
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle Communications Cloud Native Core Network Exposure Function
Netcool Operations Insight
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
Red Hat OpenShift Serverless
OpenShift sandboxed containers
OpenShift Service Mesh
Citrix Hypervisor
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
SmartFabric Storage Software
SCALANCE S615
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
e2fsprogs (Red Hat package)
libext2fs2-debuginfo
e2fsprogs-debuginfo-32bit
libcom_err2-debuginfo
libcom_err2-debuginfo-32bit
libcom_err2-32bit
libcom_err2
e2fsprogs-debugsource
e2fsprogs-debuginfo
e2fsprogs
libext2fs2
e2fsprogs-devel
libcom_err-devel
libext2fs-devel
e2fsprogs-32bit-debuginfo
libext2fs-devel-static
libcom_err-devel-static
libcom_err2-32bit-debuginfo
libext2fs-devel-32bit
libext2fs2-32bit
libext2fs2-32bit-debuginfo
libcom_err-devel-32bit
e2fsprogs (Ubuntu package)
e2fsck-static (Ubuntu package)
fuse2fs (Ubuntu package)
e2fslibs (Ubuntu package)
e2fsprogs-help
sys-fs/e2fsprogs
libcom_err
e2scrub
e2fsprogs-static
e2fsprogs-libs
libss-devel
libss
Dell EMC NetWorker vProxy
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Voice Gateway
Cloud Pak for Security (CP4S)
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
How to mitigate CVE-2022-1304
Install update from vendor's website.
E2fsprogs - update to 1.46.6
cflinuxfs3 - update to 0.304.0
Submariner - update to 0.14.0
NetObserv Operator - update to 1.1.0
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.26.0, 1.27.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
OpenShift API for Data Protection (OADP) - update to 1.1.2
SmartFabric Storage Software - update to 1.4.3
OpenShift sandboxed containers - update to 1.4.1
Migration Toolkit for Containers - addressed in versions 1.7.6, 1.7.10
e2fsprogs (Red Hat package) - addressed in versions 1.45.6-5.el8, 1.46.5-3.el9
OpenShift Service Mesh - update to 2.3.1
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.6.4
Dell EMC NetWorker vProxy - update to 4.3.0-32
OpenShift Developer Tools and Services - update to 4.9
Red Hat OpenShift Container Platform - update to 4.13.2
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.3.14, 5.4.8, 5.5.5
Red Hat Migration Toolkit for Applications - update to 6.0.1
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
Voice Gateway - addressed in versions 1.0.8.1, 1.0.8.2, 1.0.8.5
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Security (CP4S) - update to 1.10.12.0
libext2fs2-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debuginfo-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1
libcom_err2-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err2-debuginfo-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1
libcom_err2-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err2 - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debugsource - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libext2fs2 - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libext2fs-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libext2fs-devel-static - update to 1.43.8-150000.4.33.1
libcom_err-devel-static - update to 1.43.8-150000.4.33.1
libcom_err2-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libext2fs-devel-32bit - update to 1.43.8-150000.4.33.1
libext2fs2-32bit - update to 1.43.8-150000.4.33.1
libext2fs2-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libcom_err-devel-32bit - update to 1.43.8-150000.4.33.1
e2fsprogs (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
e2fsck-static (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
fuse2fs (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
e2fslibs (Ubuntu package) - update to 1.44.1-1ubuntu1.4
e2fsprogs-help - update to 1.45.6-11
e2fsprogs-debuginfo - update to 1.45.6-11
e2fsprogs-debugsource - update to 1.45.6-11
e2fsprogs-devel - update to 1.45.6-11
e2fsprogs - update to 1.45.6-11
e2fsprogs - update to 1.46.5-2
sys-fs/e2fsprogs - update to 1.46.6
libcom_err - update to 1.47.0-1
e2scrub - update to 1.47.0-1
e2fsprogs-static - update to 1.47.0-1
e2fsprogs-libs - update to 1.47.0-1
e2fsprogs-devel - update to 1.47.0-1
e2fsprogs - update to 1.47.0-1
libss-devel - update to 1.47.0-1
libss - update to 1.47.0-1
libcom_err-devel - update to 1.47.0-1
IBM MQ Operator - addressed in versions 2.0.6, 2.2.1
Cloud Pak for Network Automation - update to 2.4.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
IBM Cloud Transformation Advisor - update to 3.4.0
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.7.0.3
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
Enterprise SONiC - update to 4.4.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE S615 EEC - update to 7.2
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.1-r4, 9.3.1.0-r3
Dell Data Protection Central - update to 19.9
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1
cflinuxfs3 - update to 0.304.0
Submariner - update to 0.14.0
NetObserv Operator - update to 1.1.0
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.26.0, 1.27.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
OpenShift API for Data Protection (OADP) - update to 1.1.2
SmartFabric Storage Software - update to 1.4.3
OpenShift sandboxed containers - update to 1.4.1
Migration Toolkit for Containers - addressed in versions 1.7.6, 1.7.10
e2fsprogs (Red Hat package) - addressed in versions 1.45.6-5.el8, 1.46.5-3.el9
OpenShift Service Mesh - update to 2.3.1
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.6.4
Dell EMC NetWorker vProxy - update to 4.3.0-32
OpenShift Developer Tools and Services - update to 4.9
Red Hat OpenShift Container Platform - update to 4.13.2
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.3.14, 5.4.8, 5.5.5
Red Hat Migration Toolkit for Applications - update to 6.0.1
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
Voice Gateway - addressed in versions 1.0.8.1, 1.0.8.2, 1.0.8.5
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Security (CP4S) - update to 1.10.12.0
libext2fs2-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debuginfo-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1
libcom_err2-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err2-debuginfo-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1
libcom_err2-32bit - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err2 - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debugsource - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-debuginfo - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libext2fs2 - addressed in versions 1.42.11-16.9.1, 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libcom_err-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
libext2fs-devel - addressed in versions 1.43.8-3.17.1, 1.43.8-150000.4.33.1
e2fsprogs-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libext2fs-devel-static - update to 1.43.8-150000.4.33.1
libcom_err-devel-static - update to 1.43.8-150000.4.33.1
libcom_err2-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libext2fs-devel-32bit - update to 1.43.8-150000.4.33.1
libext2fs2-32bit - update to 1.43.8-150000.4.33.1
libext2fs2-32bit-debuginfo - update to 1.43.8-150000.4.33.1
libcom_err-devel-32bit - update to 1.43.8-150000.4.33.1
e2fsprogs (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
e2fsck-static (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
fuse2fs (Ubuntu package) - addressed in versions 1.44.1-1ubuntu1.4, 1.45.5-2ubuntu1.1, 1.46.3-1ubuntu3.1, 1.46.5-2ubuntu1.1
e2fslibs (Ubuntu package) - update to 1.44.1-1ubuntu1.4
e2fsprogs-help - update to 1.45.6-11
e2fsprogs-debuginfo - update to 1.45.6-11
e2fsprogs-debugsource - update to 1.45.6-11
e2fsprogs-devel - update to 1.45.6-11
e2fsprogs - update to 1.45.6-11
e2fsprogs - update to 1.46.5-2
sys-fs/e2fsprogs - update to 1.46.6
libcom_err - update to 1.47.0-1
e2scrub - update to 1.47.0-1
e2fsprogs-static - update to 1.47.0-1
e2fsprogs-libs - update to 1.47.0-1
e2fsprogs-devel - update to 1.47.0-1
e2fsprogs - update to 1.47.0-1
libss-devel - update to 1.47.0-1
libss - update to 1.47.0-1
libcom_err-devel - update to 1.47.0-1
IBM MQ Operator - addressed in versions 2.0.6, 2.2.1
Cloud Pak for Network Automation - update to 2.4.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
IBM Cloud Transformation Advisor - update to 3.4.0
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.7.0.3
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
Enterprise SONiC - update to 4.4.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE S615 EEC - update to 7.2
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.1-r4, 9.3.1.0-r3
Dell Data Protection Central - update to 19.9
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1
External References
Related Security Bulletins
- Out-of-bounds write in E2fsprogs
- Out-of-bounds write in cflinuxfs3
- Ubuntu update for e2fsprogs
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell EMC NetWorker vProxy
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 8 update for e2fsprogs
- Red Hat Enterprise Linux 9 update for e2fsprogs
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- IBM App Connect Enterprise Certified Container update for e2fsprogs
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in OpenShift Serverles
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Red Hat Advanced Cluster Management for Kubernetes 2.6 update for Submariner
- Multiple vulnerabilities in NetObserv Operator
- Multiple vulnerabilities in OpenShift Developer Tools and Services
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- SUSE update for e2fsprogs
- SUSE update for e2fsprogs
- SUSE update for e2fsprogs
- Out-of-bounds write in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.11
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.12
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Citrix Hypervisor
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Gentoo update for e2fsprogs
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- openEuler update for e2fsprogs
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Amazon Linux AMI update for e2fsprogs
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Multiple vulnerabilities in Enterprise SONiC Distribution
- Multiple vulnerabilities in Brocade Fabric OS
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in IBM Cloud Object System
- Anolis OS update for e2fsprogs
- Dell SmartFabric Storage Software update for third-party components
- Juniper Session Smart Router update for third-party components