CVE-2012-2100

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 03 Jul 2012, 16:00
Last modified:06 Aug 2024, 19:26

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.1 HIGH
v2.0 (nvd)
EPSS Score
0.86% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2012, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:26
Last Modified
Vulnerability information updated

Description

The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 3.2.2, on the x86 platform and unspecified other platforms, allows user-assisted remote attackers to trigger inconsistent filesystem-groups data and possibly cause a denial of service via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value). NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4307.

CVSS Metrics

  • v2.0HIGHScore: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.86% Percentile: 75%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • linuxlinux_kernel

    ≤ 3.2.1 | 3.2

References (8)