The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2011/09/14/12 | patch mailing list third party advisory |
https://github.com/torvalds/linux/commit/70945643722ffeac779d2529a348f99567fa5c33 | third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=738291 | patch third party advisory issue tracking |
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 | broken link |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=70945643722ffeac779d2529a348f99567fa5c33 |