cbcvebase.
CVE-2011-4131
published 2012-05-17

CVE-2011-4131: The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a…

PriorityP418medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
0.78%
52.5th percentile
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.9-1 (bookworm)linux 3.2.9-1 (bookworm)
debianlinux< linux 3.2.19-1 (bookworm)linux 3.2.19-1 (bookworm)
linuxlinux_kernel<= 3.3.1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.9-13.2.9-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.9-13.2.9-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.9-13.2.9-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.9-13.2.9-1

CVSS provenance

nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.