CVE-2011-4131
published 2012-05-17CVE-2011-4131: The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a…
PriorityP418medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
0.78%
52.5th percentile
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.9-1 (bookworm) | linux 3.2.9-1 (bookworm) |
| debian | linux | < linux 3.2.19-1 (bookworm) | linux 3.2.19-1 (bookworm) |
| linux | linux_kernel | <= 3.3.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.9-1 | 3.2.9-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.9-1 | 3.2.9-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.9-1 | 3.2.9-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.9-1 | 3.2.9-1 |
CVSS provenance
nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user)
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-06-15·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
han
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase th
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-05-31·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of
Red Hat
kernel: incomplete fix for CVE-2011-4131
vendor_redhat·2012-03-22·CVSS 4.6
CVE-2012-2375 [MEDIUM] kernel: incomplete fix for CVE-2011-4131
kernel: incomplete fix for CVE-2011-4131
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.2) - Affected
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.3) - Affected
Debian
CVE-2012-2375: linux - The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implement...
vendor_debian·2012·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375: linux - The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implement...
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Scope: local
bookworm: resolved (fixed in 3.2.19-1)
bullseye: resolved (fixed in 3.2.19-1)
forky: resolved (fixed in 3.2.19-1)
sid: resolved (fixed in 3.2.19-1)
trixie: resolved (fixed in 3.2.19-1)
Red Hat
kernel: nfs4_getfacl decoding kernel oops
vendor_redhat·2011-11-05·CVSS 4.6
CVE-2011-4131 [MEDIUM] kernel: nfs4_getfacl decoding kernel oops
kernel: nfs4_getfacl decoding kernel oops
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
Statement: This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 as it does not provide support for NFS ACLs. This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5. This has been addressed in Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0333.html. Future kernel updates in Red Hat Enterprise Linux 6 may address this issue.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not
Debian
CVE-2011-4131: linux - The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly hand...
vendor_debian·2011·CVSS 4.6
CVE-2011-4131 [MEDIUM] CVE-2011-4131: linux - The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly hand...
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
Scope: local
bookworm: resolved (fixed in 3.2.9-1)
bullseye: resolved (fixed in 3.2.9-1)
forky: resolved (fixed in 3.2.9-1)
sid: resolved (fixed in 3.2.9-1)
trixie: resolved (fixed in 3.2.9-1)
GHSA
GHSA-fm6c-qqgr-6pr6: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
ghsa_unreviewed·2022-05-17·CVSS 4.6
CVE-2012-2375 [MEDIUM] GHSA-fm6c-qqgr-6pr6: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
GHSA
GHSA-497c-8qgw-xqvj: The NFSv4 implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-14
CVE-2011-4131 [MEDIUM] GHSA-497c-8qgw-xqvj: The NFSv4 implementation in the Linux kernel before 3
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
OSV
CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
osv·2012-06-13·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
OSV
CVE-2011-4131: The NFSv4 implementation in the Linux kernel before 3
osv·2012-05-17·CVSS 4.6
CVE-2011-4131 [MEDIUM] CVE-2011-4131: The NFSv4 implementation in the Linux kernel before 3
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
No detection rules found.
No public exploits indexed.
Bugzilla
kernel: incomplete fix for CVE-2011-4131 [fedora-all]
bugzilla·2012-05-18·CVSS 4.6
CVE-2011-4131 [MEDIUM] kernel: incomplete fix for CVE-2011-4131 [fedora-all]
kernel: incomplete fix for CVE-2011-4131 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=822869
Please n
Bugzilla
CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
bugzilla·2012-05-18·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
The fix for CVE-2011-4131 was not complete. Malicious NFS server could still crash the clients when returns more than 2 GETATTR bitmap words in response to the FATTR4_ACL attribute request.
Upstream fixes:
20e0fa98b751facf9a1101edaefbc19c82616a68
5794d21ef4639f0e33440927bb903f9598c21e92
5a00689930ab975fdd1b37b034475017e460cf2a
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 822874]
---
Added CVE as per http://www.openwall.com/lists/oss-security/2012/05/18/13
---
kernel-3.3.7-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
---
kernel-3.3.7-1.fc16 has been pushed to the Fedora 16 stable repository. If problems stil
Bugzilla
CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops [fedora-all]
bugzilla·2011-11-11·CVSS 4.6
CVE-2011-4131 [MEDIUM] CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops [fedora-all]
CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=7
Bugzilla
CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops
bugzilla·2011-10-18·CVSS 4.6
CVE-2011-4131 [MEDIUM] CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops
CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops
nfs4_getfacl decoding causes a kernel Oops when a server returns more than 2 GETATTR bitmap words in response to the FATTR4_ACL attribute request.
While the NFS client only asks for one attribute (FATTR4_ACL) in the first bitmap word, the NFSv4 protocol allows for the server to return unbounded
bitmaps.
Upstream commit:
e5012d1f3861d18c7f3814e757c1c3ab3741dbcd - incomplete, handles only the case when 2 words are expected and 3 are returned
Proposed complete upstream patch:
http://www.spinics.net/lists/linux-nfs/msg25288.html
Acknowledgements:
Red Hat would like to thank Andy Adamson for reporting this issue.
Discussion:
Statement:
This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 as it doe
Bugzilla
CVE-2011-3208 cyrus-imapd: nntpd buffer overflow in split_wildmats()
bugzilla·2011-08-31·CVSS 7.5
CVE-2011-3208 [HIGH] CVE-2011-3208 cyrus-imapd: nntpd buffer overflow in split_wildmats()
CVE-2011-3208 cyrus-imapd: nntpd buffer overflow in split_wildmats()
A remotely exploitable buffer overflow flaw was found in Cyrus' nntpd. A malicious NNTP client would be able to exploit this to execute arbitrary code on a vulnerable nntpd server. If the 'allowanonymouslogin' option was set in imapd.conf, it could be done without authentication.
When compiled with FORTIFY_SOURCE (the default on Red Hat Enterprise Linux 5 and 6, as well as Fedora), this flaw is not exploitable and will result in a crash of the nntpd service.
The following patch will correct the flaw:
diff --git a/imap/nntpd.c b/imap/nntpd.c
index 56405d3..6b30174 100644
--- a/imap/nntpd.c
+++ b/imap/nntpd.c
@@ -4131,7 +4131,8 @@ static struct wildmat *split_wildmats(char *str)
else if (*c == '@') wild[n].not = -1; /*
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bf118a342f10dafe44b14451a1392c3254629a1fhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/081280.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0862.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1541.htmlhttp://secunia.com/advisories/48898http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2http://www.openwall.com/lists/oss-security/2011/11/12/1https://bugzilla.redhat.com/show_bug.cgi?id=747106https://github.com/torvalds/linux/commit/bf118a342f10dafe44b14451a1392c3254629a1fhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bf118a342f10dafe44b14451a1392c3254629a1fhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/081280.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0862.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1541.htmlhttp://secunia.com/advisories/48898http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2http://www.openwall.com/lists/oss-security/2011/11/12/1https://bugzilla.redhat.com/show_bug.cgi?id=747106https://github.com/torvalds/linux/commit/bf118a342f10dafe44b14451a1392c3254629a1f
2012-05-17
Published