Skip to content

e2fsprogs CVE-2022-1304

Moderate
rpkelly published GHSA-qh9x-999x-wqhr Mar 21, 2023

Package

e2fsprogs (bottlerocket)

Affected versions

< 1.13.0

Patched versions

1.13.0

Description

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

Severity

Moderate

CVE ID

CVE-2022-1304

Weaknesses

No CWEs