CVE-2012-2375
published 2012-06-13CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during…
PriorityP417medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
0.98%
59.1th percentile
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.19-1 (bookworm) | linux 3.2.19-1 (bookworm) |
| linux | linux_kernel | <= 3.3.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| ubuntu | linux-ti-omap4 | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user)
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-07-09
CVE-2012-2375 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash if it received specially crafted network
traffic.
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstal
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-07-02
CVE-2012-2375 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash if it received specially crafted network
traffic.
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstal
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes
Ubuntu
Linux kernel (Oneiric backport) vulnerability
vendor_ubuntu·2012-06-29
CVE-2012-2375 Linux kernel (Oneiric backport) vulnerability
Title: Linux kernel (Oneiric backport) vulnerability
Summary: The system could be made to crash if it received specially crafted network
traffic.
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manual
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-06-29
CVE-2012-2375 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash if it received specially crafted network
traffic.
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the
Red Hat
kernel: incomplete fix for CVE-2011-4131
vendor_redhat·2012-03-22·CVSS 4.6
CVE-2012-2375 [MEDIUM] kernel: incomplete fix for CVE-2011-4131
kernel: incomplete fix for CVE-2011-4131
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.2) - Affected
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.3) - Affected
Debian
CVE-2012-2375: linux - The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implement...
vendor_debian·2012·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375: linux - The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implement...
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Scope: local
bookworm: resolved (fixed in 3.2.19-1)
bullseye: resolved (fixed in 3.2.19-1)
forky: resolved (fixed in 3.2.19-1)
sid: resolved (fixed in 3.2.19-1)
trixie: resolved (fixed in 3.2.19-1)
GHSA
GHSA-fm6c-qqgr-6pr6: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
ghsa_unreviewed·2022-05-17·CVSS 4.6
CVE-2012-2375 [MEDIUM] GHSA-fm6c-qqgr-6pr6: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
OSV
CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
osv·2012-06-13·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375: The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4591 kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
bugzilla·2013-11-18·CVSS 4.6
CVE-2013-4591 [MEDIUM] CVE-2013-4591 kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
CVE-2013-4591 kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
Commit 1f1ea6c (included in Red Hat Enterprise Linux 6 as part of CVE-2012-2375 fix) accidently dropped the checking for too small result buffer length.
If someone uses getxattr on "system.nfs4_acl" on an NFSv4 mount supporting ACLs, the ACL has not been cached and the buffer suplied is too short, we still copy the complete ACL, resulting in kernel and user space memory corruption.
Introduced by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1f1ea6c2d9d8c0be9ec56454b05315273b5de8ce
Upstream commit:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7d3e91a89b7adbc2831334def9e494dd9892f9af
Discussion:
Statement:
This issue did not affect the version
Bugzilla
CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
bugzilla·2012-05-18·CVSS 4.6
CVE-2012-2375 [MEDIUM] CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
CVE-2012-2375 kernel: incomplete fix for CVE-2011-4131
The fix for CVE-2011-4131 was not complete. Malicious NFS server could still crash the clients when returns more than 2 GETATTR bitmap words in response to the FATTR4_ACL attribute request.
Upstream fixes:
20e0fa98b751facf9a1101edaefbc19c82616a68
5794d21ef4639f0e33440927bb903f9598c21e92
5a00689930ab975fdd1b37b034475017e460cf2a
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 822874]
---
Added CVE as per http://www.openwall.com/lists/oss-security/2012/05/18/13
---
kernel-3.3.7-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
---
kernel-3.3.7-1.fc16 has been pushed to the Fedora 16 stable repository. If problems stil
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=20e0fa98b751facf9a1101edaefbc19c82616a68http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-1580.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.2http://www.openwall.com/lists/oss-security/2012/05/18/13https://bugzilla.redhat.com/show_bug.cgi?id=822869https://github.com/torvalds/linux/commit/20e0fa98b751facf9a1101edaefbc19c82616a68http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=20e0fa98b751facf9a1101edaefbc19c82616a68http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-1580.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.2http://www.openwall.com/lists/oss-security/2012/05/18/13https://bugzilla.redhat.com/show_bug.cgi?id=822869https://github.com/torvalds/linux/commit/20e0fa98b751facf9a1101edaefbc19c82616a68
2012-06-13
Published