8.1
CVSSv3

CVE-2018-14722

Published: 15/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance up to and including 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

btrfsmaintenance project btrfsmaintenance

Vendor Advisories

Debian Bug report logs - #906131 CVE-2018-14722 Package: btrfsmaintenance; Maintainer for btrfsmaintenance is Nicholas D Steeves <nsteeves@gmailcom>; Source for btrfsmaintenance is src:btrfsmaintenance (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 14 Aug 2018 17:27:02 UTC Severit ...