Red Hat Bugzilla – Bug 1557555
CVE-2017-18224 kernel: race condition due to concurrent access to extent tree in fs/ocfs2/aops.c
Last modified: 2018-03-19 10:03:40 EDT
A flaw was found in the Linux kernel that fs/ocfs2/aops.c omits use of a semaphore and consequently has a race condition for access to the extent tree during read operations in DIRECT mode, which allows local users to cause a denial of service by modifying a certain e_cpos field. References: https://marc.info/?t=150884957800012&r=1&w=2 An upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e4c56d41eef5595035872a2ec5a483f42e8917f
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1557557]
This was fixed for Fedora with the 4.15 rebases.