CVE-2012-1090

Severity
5.5MEDIUM
EPSS
0.1%
top 81.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 13

Description

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages19 packages

NVDlinux/linux_kernel< 3.2.10
Ubuntulinux< 3.11.0-12.19+1
Ubuntulinux-aws< 4.4.0-1002.2+1
Ubuntulinux-flo< 3.4.0-1.3+1
Ubuntulinux-gke< 4.4.0-1003.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gjf7-w4hh-3pcg: The cifs_lookup function in fs/cifs/dir2022-05-13
CVEList
CVE-2012-1090: The cifs_lookup function in fs/cifs/dir2012-05-17
OSV
CVE-2012-1090: The cifs_lookup function in fs/cifs/dir2012-02-28

📋Vendor Advisories

9
Ubuntu
Linux kernel (OMAP4) vulnerabilities2012-05-31
Ubuntu
Linux kernel (OMAP4) vulnerabilities2012-05-18
Ubuntu
Linux kernel vulnerabilities2012-05-08
Ubuntu
Linux kernel (Natty backport) vulnerabilities2012-05-08
Ubuntu
Linux kernel vulnerabilities2012-05-01

💬Community

2
Bugzilla
CVE-2012-1090 kernel: cifs: dentry refcount leak when opening a FIFO on lookup leads to panic on unmount2012-02-28
Bugzilla
CVE-2012-1090 kernel: cifs: dentry refcount leak when opening a FIFO on lookup leads to panic on unmount [fedora-all]2012-02-28
CVE-2012-1090 (MEDIUM CVSS 5.5) | The cifs_lookup function in fs/cifs | cvebase.io