Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's handling of the Universal Disk Format (UDF) file system has been addressed. The issue arose from an unnecessary and complicated process of merging very long extents, which included a logic bug that corrupted file extents. This vulnerability was reproduced by syzbot, a kernel fuzzer.
The vulnerability could lead to file system corruption by improperly merging extents, causing data loss or inconsistency.
The vulnerability can be reproduced by using the UDF file system and creating scenarios where very long extents are present. The syzbot reproducer demonstrates this issue.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.