REDHAT-BUG-1148777: Medium severity Linux Linux kernel vulnerability

Published Oct 2, 2014
·
Updated

A flaw was found in the way the xfsda3fixhashpath() function of the Linux kernel's XFS file system implementation ordered directory hashes under certain conditions. A local attacker could use this flaw to corrupt the file system by creating directories, potentially resulting in kernel panic.

Upstream fix:

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c88547a8119e3b581318ab65e9b72f27f23e641d

Reproducer:

http://oss.sgi.com/cgi-bin/gitweb.cgi?p=xfs/cmds/xfstests.git;a=blob;f=src/dirhashcollide.c;h=55cec872d5061ac2ca0f56d1f11e6bf349d5bb97;hb=947ee8bd4b59770534297572b14c695e9c6e001e

References:

http://seclists.org/oss-sec/2014/q4/28 http://marc.info/?l=linux-xfs&m=139590613002926&w=2

Affected Software

2 affected components
Linux Linux kernel
SGI XFS

Event History

Oct 2, 2014
Data Sourced
via Red Hat·10:31 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1148777?

The severity of REDHAT-BUG-1148777 is considered high due to potential file system corruption and risks of kernel panic.

2

How do I fix REDHAT-BUG-1148777?

To fix REDHAT-BUG-1148777, update to the latest patched version of the Linux kernel that addresses this vulnerability.

3

What systems are affected by REDHAT-BUG-1148777?

The systems affected by REDHAT-BUG-1148777 include those running the Linux kernel and SGI XFS file system.

4

What kind of attack can leverage REDHAT-BUG-1148777?

A local attacker can leverage REDHAT-BUG-1148777 to create directories that corrupt the file system.

5

Is there a risk of data loss with REDHAT-BUG-1148777?

Yes, there is a risk of data loss with REDHAT-BUG-1148777 due to potential corruption of the file system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203