Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 260563 (CVE-2009-0747)

Summary: Kernel: <2.6.27.19 <2.6.28.7 ext4_isize in fs/ext4/ext4.h DOS (CVE-2009-0747)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: hardened, kernel
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=06a279d636734da32bb62dd2f7b0ade666f65d7c
Whiteboard: [linux <2.6.27.19] [linux >=2.6.28 <2.6.28.7]
Package list:
Runtime testing required: ---

Description Stefan Behte (RETIRED) gentoo-dev Security 2009-02-27 22:26:34 UTC
CVE-2009-0747 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0747):
  The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27
  before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high
  structure member during operations on arbitrary types of files, which
  allows local users to cause a denial of service (CPU consumption and
  error-message flood) by attempting to mount a crafted ext4 filesystem.