An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occurs because of a lack of proper validation that cached inodes are free during allocation.
4.4.0-201.2334.4.0-1121.1354.15.0-1047.49~16.04.14.15.0-1055.604.15.0-1040.42~16.04.14.15.0-58.64~16.04.14.4.0-1087.964.15.0-1021.23~16.04.14.4.0-1145.1554.4.0-1149.159Exploitability
AV:LAC:LPR:NUI:RScope
S:UImpact
C:NI:NA:HCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H