cbcvebase.
CVE-2012-2375
published 2012-06-13

CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during…

PriorityP417medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
0.98%
59.1th percentile
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.19-1 (bookworm)linux 3.2.19-1 (bookworm)
linuxlinux_kernel<= 3.3.1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
ubuntulinux-ti-omap4

CVSS provenance

nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.