Back

MEDIUM

kernel: Mounting ext2 fs e2fsprogs/tests/f_orphan as ext4 crashes system

Published Dec 28, 2015

Description

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

Affected products

Remediation

Red Hat statement

This problem did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. This issue is not planned to be corrected in future updates for Red Hat Enterprise Linux 5. This issue is rated low as exploiting it requires physical (to plug in specially prepared usb disk) or root (to mount specially prepared filesystem) access to the system. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 28, 2015
Updated Aug 6, 2024
Reserved Sep 29, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 24, 2015
ENISA EUVD
Assigner redhat
Published Dec 28, 2015
Updated Aug 6, 2024
Exploited since n/a
EUVD-2015-7430