PT-2011-4840 · Linux+3 · Linux Kernel+3

Petr Matousek

·

Published

2011-10-29

·

Updated

2023-07-27

·

CVE-2011-4077

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6
Description The issue is related to a buffer overflow in the xfs readlink function, which can cause memory corruption and a crash, potentially allowing the execution of arbitrary code. This occurs when CONFIG XFS DEBUG is disabled and an XFS image contains a symbolic link with a long pathname.
Recommendations For Linux kernel version 2.6, consider disabling the xfs readlink function as a temporary workaround until a patch is available. Restrict access to XFS images that may contain symbolic links with long pathnames to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CESA-2012_0350
CVE-2011-4077
DSA-2389-1
ELSA-2012-0350
ELSA-2012-2003
RHSA-2012:0007
RHSA-2012:0333
RHSA-2012:0350
RHSA-2012_0007
RHSA-2012_0350
USN-1286-1
USN-1291-1
USN-1292-1
USN-1293-1
USN-1299-1
USN-1300-1
USN-1301-1
USN-1302-1
USN-1303-1
USN-1304-1
USN-1311-1
USN-1312-1
USN-1322-1
USN-1330-1
USN-1336-1
USN-1340-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse