ISOMAN

CVE

CVE-2020-14314

A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

References

  1. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14314
  2. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5872331b3d91820e14716632ebb56b1399b34fe1
  3. https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
  4. https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
  5. https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
  6. https://lore.kernel.org/linux-ext4/f53e246b-647c-64bb-16ec-135383c70ad7%40redhat.com/T/#u
  7. https://usn.ubuntu.com/4576-1/
  8. https://usn.ubuntu.com/4578-1/
  9. https://usn.ubuntu.com/4579-1/
  10. https://www.starwindsoftware.com/security/sw-20210325-0003/
  11. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14314
  12. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5872331b3d91820e14716632ebb56b1399b34fe1
  13. https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
  14. https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
  15. https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
  16. https://lore.kernel.org/linux-ext4/f53e246b-647c-64bb-16ec-135383c70ad7%40redhat.com/T/#u
  17. https://usn.ubuntu.com/4576-1/
  18. https://usn.ubuntu.com/4578-1/
  19. https://usn.ubuntu.com/4579-1/
  20. https://www.starwindsoftware.com/security/sw-20210325-0003/