CVE-2017-18224: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel before 4.15, fs/ocfs2/aops.c omits use of a semaphore and consequently has a race condition for access to the extent tree during read operations in DIRECT mode, which allows local users to cause a denial of service (BUG) by modifying a certain e_cpos field.
Affected products
- Linux Linux Kernel: before 4.15 (fixed in 4.15)
Published 2018-03-12. Last modified 2026-06-17.