The vendor explicitly identifies these products as affected by this CVE.
- e2fsprogs-devel as a component of Red Hat Enterprise Linux 6
- e2fsprogs-libs as a component of Red Hat Enterprise Linux 6
- e2fsprogs.src as a component of Red Hat Enterprise Linux 6
- libcom_err as a component of Red Hat Enterprise Linux 6
- libcom_err-devel as a component of Red Hat Enterprise Linux 6
- libss as a component of Red Hat Enterprise Linux 6
- libss-devel as a component of Red Hat Enterprise Linux 6
- e2fsprogs as a component of Red Hat Enterprise Linux 7
- e2fsprogs-devel as a component of Red Hat Enterprise Linux 7
- e2fsprogs-libs as a component of Red Hat Enterprise Linux 7
- e2fsprogs-static as a component of Red Hat Enterprise Linux 7
- e2fsprogs.src as a component of Red Hat Enterprise Linux 7
- Summary
- An out-of-bounds read/write vulnerability was found in e2fsprogs. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
