e2fsprogs: Out-of-bounds write in e2fsck/rehash.c (CVE-2019-5188)
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Fixed In Version:
e2fsprogs 1.45.5
References:
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973
- https://nvd.nist.gov/vuln/detail/CVE-2019-5188
Patches:
- https://github.com/tytso/e2fsprogs/commit/8dd73c149f418238f19791f9d666089ef9734dff
- https://github.com/tytso/e2fsprogs/commit/71ba13755337e19c9a826dfc874562a36e1b24d3