Vulnerability Details CVE-2018-14722
An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.9%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 9.3
Products affected by CVE-2018-14722
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.1
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.1.1
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.1.2
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.2
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.3
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.3.1
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.4
-
cpe:2.3:a:btrfsmaintenance_project:btrfsmaintenance:0.4.1