CVE-2011-0542
published 2011-09-02CVE-2011-0542: fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary…
PriorityP411low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.32%
24.4th percentile
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fuse | < fuse 2.8.5-1 (bookworm) | fuse 2.8.5-1 (bookworm) |
| fuse | fuse | <= 2.8.5 | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
| fuse | fuse | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_redhat6.9MEDIUM
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w2gc-fxmq-hpfh: fusermount in fuse 2
ghsa_unreviewed·2022-05-17
CVE-2011-0542 [LOW] GHSA-w2gc-fxmq-hpfh: fusermount in fuse 2
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
OSV
CVE-2011-0542: fusermount in fuse 2
osv·2011-09-02·CVSS 3.3
CVE-2011-0542 [LOW] CVE-2011-0542: fusermount in fuse 2
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
Red Hat
kernel: drivers/scsi/mpt2sas: prevent heap overflows
vendor_redhat·2011-04-05·CVSS 6.9
CVE-2011-1494 [MEDIUM] CWE-119 kernel: drivers/scsi/mpt2sas: prevent heap overflows
kernel: drivers/scsi/mpt2sas: prevent heap overflows
Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 4 as it did not provide support for MPT (Message Passing
Technology) based controllers. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, and https://rhn.redhat.com/errata/RHSA-2011-0542.html, and https://rhn.redhat.com/errata/RHSA-2011-1
Red Hat
kernel: fs/partitions: Corrupted OSF partition table infoleak
vendor_redhat·2011-03-15·CVSS 2.1
CVE-2011-1163 [LOW] kernel: fs/partitions: Corrupted OSF partition table infoleak
kernel: fs/partitions: Corrupted OSF partition table infoleak
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, https://rhn.redhat.com/errata/RHSA-2011-0542.html, and https://rhn.redhat.com/errata/RHSA-2011-0500.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for
this issue is not currently pl
Red Hat
kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab
vendor_redhat·2011-03-05·CVSS 4.9
CVE-2011-1090 [MEDIUM] kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab
kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab
The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not backport the upstream commit 4b580ee3 that introduced this issue. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0429.html, https://rhn.redhat.com/errata/RHSA-2011-0542.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html.
Package:
Ubuntu
FUSE vulnerabilities
vendor_ubuntu·2011-02-28
CVE-2011-0541 FUSE vulnerabilities
Title: FUSE vulnerabilities
It was discovered that FUSE would incorrectly follow symlinks when checking
mountpoints under certain conditions. A local attacker, with access to use
FUSE, could unmount arbitrary locations, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
kernel: fs/partitions: Validate map_count in Mac partition tables
vendor_redhat·2011-02-17·CVSS 4.9
CVE-2011-1010 [MEDIUM] kernel: fs/partitions: Validate map_count in Mac partition tables
kernel: fs/partitions: Validate map_count in Mac partition tables
Buffer overflow in the mac_partition function in fs/partitions/mac.c in the Linux kernel before 2.6.37.2 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via a malformed Mac OS partition table.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0429.html, https://rhn.redhat.com/errata/RHSA-2011-0542.html and https://rhn.redhat.com/errata/RHSA-2011-0500.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates
Red Hat
kernel: thp: prevent hugepages during args/env copying into the user stack
vendor_redhat·2011-02-15·CVSS 4.9
CVE-2011-0999 [MEDIUM] kernel: thp: prevent hugepages during args/env copying into the user stack
kernel: thp: prevent hugepages during args/env copying into the user stack
mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact via a crafted application.
Statement: This issue only affects Red Hat Enterprise Linux 6. The version of Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG as they did not include upstream commit 71e3aac0 that introduced the problem. We have addressed this in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2011-0542.html.
Red Hat
kernel: potential kernel deadlock when creating circular epoll file structures
vendor_redhat·2011-02-05·CVSS 4.9
CVE-2011-1082 [MEDIUM] kernel: potential kernel deadlock when creating circular epoll file structures
kernel: potential kernel deadlock when creating circular epoll file structures
fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
Statement: This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5. This was addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0542.html and https://rhn.redhat.com/errata/RHSA-2011-0500.html.
Package: kernel (Red Hat Enterprise Linux 4) - Affected
Package: kernel (Re
Debian
CVE-2011-0542: fuse - fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before perfor...
vendor_debian·2011·CVSS 3.3
CVE-2011-0542 [LOW] CVE-2011-0542: fuse - fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before perfor...
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.8.5-1)
bullseye: resolved (fixed in 2.8.5-1)
sid: resolved (fixed in 2.8.5-1)
trixie: resolved (fixed in 2.8.5-1)
Red Hat
fuse: unprivileged user can unmount arbitrary locations via symlink attack
vendor_redhat·2010-11-02·CVSS 3.3
CVE-2011-0542 [LOW] fuse: unprivileged user can unmount arbitrary locations via symlink attack
fuse: unprivileged user can unmount arbitrary locations via symlink attack
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. On Red Hat Enterprise Linux 5 and 6, a user must be a member of the 'fuse' group in order to use FUSE. Due to the risks associated with fixing this bug on Red Hat Enterprise Linux 5, and because of the group restrictions in place, we currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.
Package: fuse (Red Hat Enterprise Linux 5) - Will not fix
Package: util-linux (Red Hat Enterprise Linux 5) - Will not fix
Package
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0999 kernel: thp: prevent hugepages during args/env copying into the user stack
bugzilla·2011-02-17·CVSS 4.9
CVE-2011-0999 [MEDIUM] CVE-2011-0999 kernel: thp: prevent hugepages during args/env copying into the user stack
CVE-2011-0999 kernel: thp: prevent hugepages during args/env copying into the user stack
Transparent hugepages can only be created if rmap is fully functional. A specially crafted binary could allow the user stack to grow huge and backed by hugepages without this patch while is_vma_temporary_stack() is true.
This also optmizes away some harmless but unnecessary setting of khugepaged_scan.address and it switches some BUG_ON to VM_BUG_ON.
Discussion:
Upstream commit:
http://git.kernel.org/linus/a7d6e4ecdb7648478ddec76d30d87d03d6e22b31
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0542 https://rhn.redhat.com/errata/RHSA-2011-0542.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6.0.Z - Server
Bugzilla
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
bugzilla·2010-11-08·CVSS 5.8
CVE-2010-3879 [MEDIUM] CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack
It was reported [1],[2] that the fusermount tool was vulnerable to a race condition between mounting a user filesystem and updating mtab using the standard mount command. If a user were able to win the race, the real mount entry and the mtab entry would differ, making the fuse-mounted filesystem not unmountable by an unprivileged user. Crafted mtab entries can then be used to trick fusermount into believing that a certain part of the filesystem is a user-space filesystem, and will unmount what should be a privileged filesystem (as demonstrated by unmounting /proc).
According to the SUSE bug report [3], this would affect fuse versions before 2.8.2 or util-linu
http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=1e7607ff89c65b005f69e27aeb1649d624099873http://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4http://fuse.git.sourceforge.net/git/gitweb.cgi?p=fuse/fuse%3Ba=commit%3Bh=1e7607ff89c65b005f69e27aeb1649d624099873http://www.openwall.com/lists/oss-security/2011/02/02/2http://www.openwall.com/lists/oss-security/2011/02/03/5http://www.openwall.com/lists/oss-security/2011/02/08/4
2011-09-02
Published