CVE-2019-5188: malicious fs can cause stack underflow in e2fsck

Related Vulnerabilities: CVE-2019-5188  

Debian Bug report logs - #948508
CVE-2019-5188: malicious fs can cause stack underflow in e2fsck

version graph

Reported by: "Theodore Y. Ts'o" <tytso@mit.edu>

Date: Thu, 9 Jan 2020 16:03:02 UTC

Severity: grave

Tags: security

Found in versions e2fsprogs/1.44.5-1+deb10u2, e2fsprogs/1.43.4-2+deb9u1, e2fsprogs/1.43.4-2

Fixed in version e2fsprogs/1.45.5-1

Done: Salvatore Bonaccorso <carnil@debian.org>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Theodore Y. Ts'o <tytso@mit.edu>:
Bug#948508; Package e2fsprogs. (Thu, 09 Jan 2020 16:03:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Theodore Y. Ts'o" <tytso@mit.edu>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Theodore Y. Ts'o <tytso@mit.edu>. (Thu, 09 Jan 2020 16:03:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Theodore Y. Ts'o" <tytso@mit.edu>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2019-5188: malicious fs can cause stack underflow in e2fsck
Date: Thu, 09 Jan 2020 10:58:29 -0500
Package: e2fsprogs
Version: 1.43.4-2+deb9u1
Severity: grave
Tags: security
Justification: user security hole

E2fsprogs 1.45.5 contains a bug fix for CVE-2019-5188 / TALOS-2019-0973.
The following commits need to be backported to address this
vulnerability in Debian Buster and Debian Stretch:

8dd73c14 - e2fsck: abort if there is a corrupted directory block when rehashing
71ba1375 - e2fsck: don't try to rehash a deleted directory

The impact of this bug is that if an attacker can tricker the system
into running e2fsck on an untrustworthy file system, a maliciously
crafted file system could result in a stack underflow.  The primary
concern is on 32-bit systems; due to limitations in the kind of stack
corruption which can be triggered due to this bug, it is probably not
exploitable on 64-bit systems.



Marked as found in versions e2fsprogs/1.43.4-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 09 Jan 2020 16:18:02 GMT) (full text, mbox, link).


Marked as found in versions e2fsprogs/1.44.5-1+deb10u2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 09 Jan 2020 16:18:03 GMT) (full text, mbox, link).


Marked as fixed in versions e2fsprogs/1.45.5-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 09 Jan 2020 16:18:03 GMT) (full text, mbox, link).


Marked Bug as done Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 09 Jan 2020 16:18:04 GMT) (full text, mbox, link).


Notification sent to "Theodore Y. Ts'o" <tytso@mit.edu>:
Bug acknowledged by developer. (Thu, 09 Jan 2020 16:18:05 GMT) (full text, mbox, link).


Message sent on to "Theodore Y. Ts'o" <tytso@mit.edu>:
Bug#948508. (Thu, 09 Jan 2020 16:18:06 GMT) (full text, mbox, link).


Message #18 received at 948508-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 948508-submitter@bugs.debian.org
Subject: found 948508 in 1.43.4-2, found 948508 in 1.44.5-1+deb10u2, closing 948508
Date: Thu, 09 Jan 2020 17:15:18 +0100
found 948508 1.43.4-2
found 948508 1.44.5-1+deb10u2
close 948508 1.45.5-1
thanks





Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Jan 10 09:24:54 2020; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.