Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4131

Опубликовано: 05 нояб. 2011
Источник: redhat
CVSS2: 4.6
EPSS Низкий

Описание

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

Отчет

This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 as it does not provide support for NFS ACLs. This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5. This has been addressed in Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0333.html. Future kernel updates in Red Hat Enterprise Linux 6 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2012:086219.06.2012
Red Hat Enterprise Linux 6.2 EUS - Server and Compute Node OnlykernelFixedRHSA-2012:154104.12.2012
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2012:033323.02.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=747106kernel: nfs4_getfacl decoding kernel oops

EPSS

Процентиль: 57%
0.00355
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

nvd
больше 13 лет назад

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

debian
больше 13 лет назад

The NFSv4 implementation in the Linux kernel before 3.2.2 does not pro ...

github
больше 3 лет назад

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

oracle-oval
около 13 лет назад

ELSA-2012-0862: Oracle Linux 6 kernel security, bug fix and enhancement update (MODERATE)

EPSS

Процентиль: 57%
0.00355
Низкий

4.6 Medium

CVSS2