Candidate: CVE-2020-6108 PublicDate: 2020-10-15 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6108 https://talosintelligence.com/vulnerability_reports/TALOS-2020-1050 Description: An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_f2fs-tools: upstream_f2fs-tools: needs-triage precise/esm_f2fs-tools: DNE trusty_f2fs-tools: ignored (out of standard support) trusty/esm_f2fs-tools: DNE xenial_f2fs-tools: ignored (end of standard support, was needs-triage) bionic_f2fs-tools: needs-triage focal_f2fs-tools: needs-triage groovy_f2fs-tools: ignored (reached end-of-life) hirsute_f2fs-tools: ignored (reached end-of-life) impish_f2fs-tools: needs-triage jammy_f2fs-tools: needs-triage devel_f2fs-tools: needs-triage