PT-2012-2256 · Linux+3 · Linux Kernel+3

Wang Xi

·

Published

2012-01-13

·

Updated

2023-02-13

·

CVE-2012-0038

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.1.9
Description The issue is caused by an integer overflow in the xfs acl from disk function, which can lead to a heap-based buffer overflow when a local user interacts with a filesystem containing a malformed ACL, resulting in a denial of service (panic).
Recommendations For Linux kernel versions prior to 3.1.9, update to version 3.1.9 or later to resolve the issue.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

CESA-2012_0350
CVE-2012-0038
RHSA-2012:0333
RHSA-2012:0350
RHSA-2012:1042
RHSA-2012_0350
USN-1212-1
USN-1356-1
USN-1361-1
USN-1362-1
USN-1363-1
USN-1364-1
USN-1384-1
USN-1386-1
USN-1387-1
USN-1388-1
USN-1389-1
USN-1391-1
USN-1394-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse