USN-5464-1: e2fsprogs vulnerability
7 June 2022
e2fsprogs could be made to crash or possibly run programs if it processed a specially crafted file system image.
Releases
Packages
- e2fsprogs - ext2/ext3/ext4 file system utilities
Details
Nils Bars discovered that e2fsprogs incorrectly handled certain file
systems. A local attacker could use this issue with a crafted file
system image to possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
Ubuntu 21.10
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
-
e2fsprogs
-
1.42.13-1ubuntu1.2+esm1
Available with Ubuntu Pro
-
e2fslibs
-
1.42.13-1ubuntu1.2+esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
e2fsprogs
-
1.42.9-3ubuntu1.3+esm3
Available with Ubuntu Pro
-
e2fsck-static
-
1.42.9-3ubuntu1.3+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.