cbcvebase.
CVE-2011-1585
published 2013-06-08

CVE-2011-1585: The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions…

PriorityP48low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.49%
39.6th percentile
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.

Affected

3 ranges
VendorProductVersion rangeFixed in
linuxlinux_kernel< 2.6.362.6.36
openstacknova>= 0 < 12.0.0a012.0.0a0
susesuse_linux_enterprise_server

CVSS provenance

nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat9.3CRITICAL
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.