Hide Forgot
The fs/ext4/inline.c:ext4_read_inline_data() function in the Linux kernel performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode. The unbound copy can cause memory corruption or possible privilege escalation. An upstream bug: https://bugzilla.kernel.org/show_bug.cgi?id=199803 Upstream patches: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=117166efb1ee8f13c38f9e96b258f16d4923f888 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=eb9b5f01c33adebc31cbc236c02695f605b0e417
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1582360]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:0525 https://access.redhat.com/errata/RHSA-2019:0525