Critical erofs-utils Security Advisory: Prevent Remote Code Execution in Mageia
Summary
Heap Buffer Overflow in the erofsfsck_dirent_iter function in
fsck/main.c in erofs-utils v1.6 allows remote attackers to execute
arbitrary code via a crafted erofs filesystem image.
References
- https://bugs.mageia.org/show_bug.cgi?id=32272
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33551
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33552
Resolution
MGASA-2024-0241 - Updated erofs-utils packages fix security vulnerabilities
SRPMS
- 9/core/erofs-utils-1.7.1-1.mga9