CVE-2018-18690 Details
Description
In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.17 |
CPE
Remediation
| |
| canonical ubuntu linux | 12.04 14.04 16.04 18.04 |
CPE
Remediation
| |
| debian debian linux | 8.0 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Apr 3, 2019 | Modified Analysis | [email protected] |
| Apr 1, 2019 | CVE Modified | [email protected] |
| Mar 27, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Mar 8, 2019 | Modified Analysis | [email protected] |
| Jan 15, 2019 | CVE Modified | [email protected] |
| Dec 21, 2018 | CVE Modified | [email protected] |
| Dec 10, 2018 | Initial Analysis | [email protected] |
| Oct 30, 2018 | CVE Modified | [email protected] |