Tracker / CVE-2018-11412
CVE-2018-11412
Medium 5.9
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| linux | linux_kernel · 4.13 → 4.16.11 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.