Scheduled maintenance: Some features related to account registration and licensing may be temporarily unavailable from Friday (May 8) at 1 PM to Sunday (May 10) at 5 PM (PST).
HomeDefectsLIN1023-786
Fixed

LIN1023-786 : Security Advisory - erofs-utils - CVE-2023-33551

Created: Jun 2, 2023    Updated: Apr 17, 2024
Resolved Date: Jul 24, 2023
Found In Version: 10.23.30.1
Fix Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.

CREATE(Triage):(User=admin) CVE-2023-33551 (https://nvd.nist.gov/vuln/detail/CVE-2023-33551)

CVEs