Vulnerabilities > CVE-2018-14722 - Unspecified vulnerability in Btrfsmaintenance Project Btrfsmaintenance
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though).
Vulnerable Configurations
References
- http://www.openwall.com/lists/oss-security/2018/08/14/7
- http://www.openwall.com/lists/oss-security/2019/06/27/7
- http://www.openwall.com/lists/oss-security/2019/06/28/1
- http://www.openwall.com/lists/oss-security/2019/06/28/2
- https://bugzilla.suse.com/show_bug.cgi?id=1102721
- http://www.openwall.com/lists/oss-security/2018/08/14/7
- https://bugzilla.suse.com/show_bug.cgi?id=1102721
- http://www.openwall.com/lists/oss-security/2019/06/28/2
- http://www.openwall.com/lists/oss-security/2019/06/28/1
- http://www.openwall.com/lists/oss-security/2019/06/27/7