CVE-2012-2375
Linux Kernel < 3.3.2 - Denial of Service via NFSv4 FATTR4_ACL Reply
Title source: llmDescription
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
References (7)
Core 7
Core References
Patch x_refsource_confirm
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=20e0fa98b751facf9a1101edaefbc19c82616a68
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1580.html
Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.2
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=822869
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/18/13
Exploit, Patch x_refsource_confirm
https://github.com/torvalds/linux/commit/20e0fa98b751facf9a1101edaefbc19c82616a68
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=139447903326211&w=2
Scores
EPSS
0.0098
EPSS Percentile
58.9%
Details
CWE
CWE-189
Status
published
Products (2)
linux/linux_kernel
3.3 (8 CPE variants)
linux/linux_kernel
< 3.3.1
Published
Jun 13, 2012
Tracked Since
Feb 18, 2026