Bugzilla – Bug 1100060
VUL-0: CVE-2018-13098: kernel-source: f2fs slab out-of-bounds read in fs/f2fs/inode.c
Last modified: 2018-10-17 19:13:32 UTC
An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode. https://git.kernel.org/pub/scm/linux/kernel/git/chao/linux.git/commit/?h=f2fs-dev&id=346886775c5fa6a541c0148bbecc0554ab9d6dad https://git.kernel.org/pub/scm/linux/kernel/git/chao/linux.git/commit/?h=f2fs-dev&id=346886775c5fa6a541c0148bbecc0554ab9d6dad https://bugzilla.kernel.org/show_bug.cgi?id=200173
As per https://bugzilla.opensuse.org/show_bug.cgi?id=1109665 this won't be fixed.
Confirmed that this does not affect SLE kernels, but openSUSE kernels. (CONFIG_F2FS_FS) As per bug 1109665 the f2fs modules are slated to be disabled. Takashi, can I ask you to reference these bugs in the next openSUSE kernel submission as removed modules? Also just to make sure that the module cannot be loaded even from a previous module tree?
This is an autogenerated message for OBS integration: This bug (1100060) was mentioned in https://build.opensuse.org/request/show/639718 42.3 / kernel-source
This is an autogenerated message for OBS integration: This bug (1100060) was mentioned in https://build.opensuse.org/request/show/641142 42.3 / kernel-source
openSUSE-SU-2018:3202-1: An update that solves 13 vulnerabilities and has 74 fixes is now available. Category: security (important) Bug References: 1012382,1044189,1050549,1063026,1065600,1066223,1082519,1082863,1082979,1084427,1084536,1088087,1089343,1090535,1094244,1094555,1094562,1095344,1095753,1096052,1096547,1099597,1099810,1100056,1100059,1100060,1100061,1100062,1102495,1102715,1102870,1102875,1102877,1102879,1102882,1102896,1103156,1103269,1103308,1103405,1105428,1105795,1106095,1106105,1106240,1106293,1106434,1106512,1106594,1106934,1107318,1107829,1107924,1108096,1108170,1108240,1108315,1108399,1108803,1108823,1109333,1109336,1109337,1109441,1109806,1110006,1110297,1110337,1110363,1110468,1110600,1110601,1110602,1110603,1110604,1110605,1110606,1110611,1110612,1110613,1110614,1110615,1110616,1110618,1110619,1110930,1111363 CVE References: CVE-2018-13096,CVE-2018-13097,CVE-2018-13098,CVE-2018-13099,CVE-2018-13100,CVE-2018-14613,CVE-2018-14617,CVE-2018-14633,CVE-2018-16276,CVE-2018-16597,CVE-2018-17182,CVE-2018-7480,CVE-2018-7757 Sources used: openSUSE Leap 42.3 (src): kernel-debug-4.4.159-73.1, kernel-default-4.4.159-73.1, kernel-docs-4.4.159-73.2, kernel-obs-build-4.4.159-73.1, kernel-obs-qa-4.4.159-73.1, kernel-source-4.4.159-73.1, kernel-syms-4.4.159-73.1, kernel-vanilla-4.4.159-73.1