Type confusion in shiftfs
Published Apr 23, 2020
7.8
HIGHCVSS 3.1
EPSS 1.10%
Description
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info *". As the private_data is not required to be a pointer, an attacker can use this to cause a denial of service or possibly execute arbitrary code.
Affected products
-
- Version 5.0 kernelStatusaffectedConstraints<5.0.0-35.38
- Version 5.3.0-11.12StatusaffectedConstraints<5.3 kernel*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Ubuntu | Shiftfs in the Linux kernel | n/a |
|
Configuration 1
- 5.0
- 5.3
Configuration 2
- 18.04
- 19.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/eoan/commit/?id=5df147c8140efc71ac0879ae3b0057f577226d4c x_refsource_MISCMailing ListPatchThird Party Advisory
- https://usn.ubuntu.com/usn/usn-4183-1 x_refsource_MISCVendor Advisory
- https://usn.ubuntu.com/usn/usn-4184-1 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/eoan/commit/?id=5df147c8140efc71ac0879ae3b0057f577226d4c | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| https://usn.ubuntu.com/usn/usn-4183-1 | x_refsource_MISCVendor Advisory | |
| https://usn.ubuntu.com/usn/usn-4184-1 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.