Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4updateinline_data(). An attacker could use this to cause a system crash and a denial of service.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10880.json"
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8cdb5240ec5928b20490a2bb34cb87e9a5f40226",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "76997228818557149449083010032886716435",
"length": 1016.0
},
"id": "CVE-2018-10880-5a7d0427",
"signature_type": "Function",
"target": {
"file": "fs/ext4/xattr.c",
"function": "ext4_xattr_make_inode_space"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8cdb5240ec5928b20490a2bb34cb87e9a5f40226",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"286714041883710277410678835068697702071",
"285092418401714019751627889997451989974",
"123701783545714686007882522533180140873",
"96582868938451439974198785853347288824"
],
"threshold": 0.9
},
"id": "CVE-2018-10880-deec85ab",
"signature_type": "Line",
"target": {
"file": "fs/ext4/xattr.c"
}
}
]