CVE-2011-4132
published 2012-01-27CVE-2011-4132: The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.49%
39.3th percentile
The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| linux | linux_kernel | >= 0 < 4.2.0-16.19 | 4.2.0-16.19 |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_ubuntu6.9MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-01-23·CVSS 2.1
CVE-2011-2203 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Clement Lecigne discovered a bug in the HFS filesystem. A local attacker
could exploit this to cause a kernel oops. (CVE-2011-2203)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
A flaw was found in how the Linux kernel handles user-defined key types. An
unprivileged local user could exploit this to crash the system.
(CVE-2011-4110)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Cle
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-01-23·CVSS 2.1
CVE-2011-2203 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Clement Lecigne discovered a bug in the HFS filesystem. A local attacker
could exploit this to cause a kernel oops. (CVE-2011-2203)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
A flaw was found in how the Linux kernel handles user-defined key types. An
unprivileged local user could exploit this to crash the system.
(CVE-2011-4110)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-01-13·CVSS 2.1
CVE-2011-2203 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Clement Lecigne discovered a bug in the HFS filesystem. A local attacker
could exploit this to cause a kernel oops. (CVE-2011-2203)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
A flaw was found in how the Linux kernel handles user-defined key types. An
unprivileged local user could exploit this to crash the system.
(CVE-2011-4110)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Cleme
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-12-19·CVSS 2.1
CVE-2011-3638 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Peter Huewe discovered an information leak in the handling of reading
security-related TPM data. A local, unprivileged user could read the
results of a previous TPM command. (CVE-2011-1162)
Zheng Liu discovered a flaw in how the ext4 filesystem splits extents. A
local unprivileged attacker could exploit this to crash the system, leading
to a denial of service. (CVE-2011-3638)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker cou
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-12-19·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Clement Lecigne discovered a bug in the HFS file system bounds checking.
When a malformed HFS file system is mounted a loca
Ubuntu
Linux kernel (FSL-IMX51) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel (FSL-IMX51) vulnerabilities
Title: Linux kernel (FSL-IMX51) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Clement Lecigne discovered a bug in the HFS file system bounds checking.
When a malformed HFS file system is mounted a local user could crash the
system or gain root privileges. (CVE-2011-4330)
Instructions: After a standard system update you need to reboot your computer to make
all the ne
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Clement Lecigne discovered a bug in the HFS file system bounds checking.
When a malformed HFS file system
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 2.1
CVE-2011-1162 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Peter Huewe discovered an information leak in the handling of reading
security-related TPM data. A local, unprivileged user could read the
results of a previous TPM command. (CVE-2011-1162)
Zheng Liu discovered a flaw in how the ext4 filesystem splits extents. A
local unprivileged attacker could exploit this to crash the system, leading
to a denial of service. (CVE-2011-3638)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attack
Ubuntu
Linux kernel (Marvell DOVE) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 2.1
CVE-2011-1162 [LOW] Linux kernel (Marvell DOVE) vulnerabilities
Title: Linux kernel (Marvell DOVE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Peter Huewe discovered an information leak in the handling of reading
security-related TPM data. A local, unprivileged user could read the
results of a previous TPM command. (CVE-2011-1162)
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
Scot Doyle discovered that the bridge networking interface incorrectly
handled certain network packets. A remote attacker could exploit this to
crash the system, leading to a denial of service. (CVE-2011-4087)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file s
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-12-13·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
A bug was found in the way headroom check was performed in
udp6_ufo_fragment() function. A remote attacker could us
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-12-08·CVSS 6.9
CVE-2011-4326 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
A bug was found in the way headroom check was performed in
udp6_ufo_fragment() function. A remote attacker could use this f
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-12-08·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
Clement Lecigne discovered a bug in the HFS file system bounds checking.
When a malformed HFS file system is mounted a local user could crash the
system or gain root privileges. (CVE-2011-4330)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chan
Ubuntu
Linux kernel (Maverick backport) vulnerabilities
vendor_ubuntu·2011-12-08·CVSS 6.9
CVE-2011-4077 [MEDIUM] Linux kernel (Maverick backport) vulnerabilities
Title: Linux kernel (Maverick backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the XFS filesystem's handling of pathnames. A local
attacker could exploit this to crash the system, leading to a denial of
service, or gain root privileges. (CVE-2011-4077)
Nick Bowler discovered the kernel GHASH message digest algorithm
incorrectly handled error conditions. A local attacker could exploit this
to cause a kernel oops. (CVE-2011-4081)
A flaw was found in the Journaling Block Device (JBD). A local attacker
able to mount ext3 or ext4 file systems could exploit this to crash the
system, leading to a denial of service. (CVE-2011-4132)
A bug was found in the way headroom check was performed in
udp6_ufo_fragment() function. A remote attac
Red Hat
kernel: jbd/jbd2: invalid value of first log block leads to oops
vendor_redhat·2011-11-01·CVSS 2.1
CVE-2011-4132 [LOW] kernel: jbd/jbd2: invalid value of first log block leads to oops
kernel: jbd/jbd2: invalid value of first log block leads to oops
The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0007.html, https://rhn.redhat.com/errata/RHSA-2012-0350.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat
Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle,
https://access.redhat.c
GHSA
GHSA-cwc2-grvm-9422: The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2
ghsa_unreviewed·2022-05-14
CVE-2011-4132 [LOW] CWE-20 GHSA-cwc2-grvm-9422: The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2
The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
OSV
CVE-2011-4132: The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2
osv·2011-11-18·CVSS 2.1
CVE-2011-4132 [LOW] CVE-2011-4132: The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2
The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops [fedora-all]
bugzilla·2011-11-11·CVSS 2.1
CVE-2011-4132 [LOW] CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops [fedora-all]
CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new
Bugzilla
CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops
bugzilla·2011-11-11·CVSS 2.1
CVE-2011-4132 [LOW] CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops
CVE-2011-4132 kernel: jbd/jbd2: invalid value of first log block leads to oops
A flaw was found in the way Linux kernel's Journaling Block Device (JBD) handled invalid log first block value. An attacker able to mount malicious ext3 or ext4 image could use this flaw to crash the system.
Upstream commit:
8762202dd0d6e46854f786bdb6fb3780a1625efe
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 753346]
---
Statement:
This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0007.html, https://rhn.redhat.com/errata/RHSA-2012-0350.html, and https://rhn.redhat.com/errata/RHSA
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=8762202dd0d6e46854f786bdb6fb3780a1625efehttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/48898http://securitytracker.com/id?1026325http://www.openwall.com/lists/oss-security/2011/11/11/6http://www.openwall.com/lists/oss-security/2011/11/13/4http://www.securityfocus.com/bid/50663http://xorl.wordpress.com/2011/12/08/cve-2011-4132-linux-kernel-jbdjbd2-local-dos/https://bugzilla.redhat.com/show_bug.cgi?id=753341http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=8762202dd0d6e46854f786bdb6fb3780a1625efehttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/48898http://securitytracker.com/id?1026325http://www.openwall.com/lists/oss-security/2011/11/11/6http://www.openwall.com/lists/oss-security/2011/11/13/4http://www.securityfocus.com/bid/50663http://xorl.wordpress.com/2011/12/08/cve-2011-4132-linux-kernel-jbdjbd2-local-dos/https://bugzilla.redhat.com/show_bug.cgi?id=753341
2012-01-27
Published