LWN.net Logo

kernel: multiple ext4 denial of service vulnerabilities

Package(s):linux-2.6 CVE #(s):CVE-2009-0745 CVE-2009-0746 CVE-2009-0747 CVE-2009-0748
Created:March 23, 2009 Updated:September 16, 2009
Description:

From the Debian advisory:

CVE-2009-0745: Peter Kerwien discovered an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) during a resize operation.

CVE-2009-0746: Sami Liedes reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when accessing a specially crafted corrupt filesystem.

CVE-2009-0747: David Maciejak reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem.

CVE-2009-0748: David Maciejak reported an additional issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem.

Alerts:
CentOS CESA-2009:1243 2009-09-15
Red Hat RHSA-2009:1243-02 2009-09-02
Debian DSA-1787-1 2009-05-02
Ubuntu USN-751-1 2009-04-07
Debian DSA-1749-1 2009-03-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds