An issue was discovered in xfsagfverify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive duration via an XFS v5 image with crafted metadata, aka CID-d0c7feaf8767.
[
{
"id": "CVE-2020-12655-6eefdf2e",
"deprecated": false,
"digest": {
"line_hashes": [
"152306472321763374190823013707677727246",
"91522299214251894988553949812457276547",
"47499290372092382151916015078307639289",
"190553405638394872288622171176185105926",
"201825137631027776777405974831622784482",
"216121449075576047761961909978068049019",
"247634619722965659333680445561594366319",
"31974364983613946044926994281143681282",
"199272895490894431667363104981249105465"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "fs/xfs/libxfs/xfs_alloc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@d0c7feaf87678371c2c09b3709400be416b2dc62",
"signature_type": "Line"
},
{
"id": "CVE-2020-12655-d8c84480",
"deprecated": false,
"digest": {
"function_hash": "71800253256359944274928221578292279107",
"length": 1635.0
},
"signature_version": "v1",
"target": {
"function": "xfs_agf_verify",
"file": "fs/xfs/libxfs/xfs_alloc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@d0c7feaf87678371c2c09b3709400be416b2dc62",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12655.json"