CVE-2011-1585: Low severity linux kernel vulnerability
Last updated 24 July 2024
Other sources
The cifsfindsmbses function in fs/cifs/connect.c in the Linux kerne ...
— Debian
When one user has mounted a cifs share that requires authentication, another user could mount the same share without knowing the correct password.
A way to exploit this would be through mount.cifs if it's installed setuid root.
On Red Hat Enterprise Linux, mount.cifs is not root setuid by default.
Upstream commits: http://git.kernel.org/linus/4ff67b720c02c36e54d55b88c2931879b7db1cd2 http://git.kernel.org/linus/fc87a40677bbe0937e2ff0642c7e83c9a4813f3d http://git.kernel.org/linus/24e6cf92fde1f140d8eb0bf7cd24c2c78149b6b2
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1585?
CVE-2011-1585 is considered a medium severity vulnerability that affects the Linux kernel up to version 2.6.36.
How do I fix CVE-2011-1585?
To fix CVE-2011-1585, upgrade to a Linux kernel version higher than 2.6.36 or the appropriate patched version provided by your distribution.
Which systems are affected by CVE-2011-1585?
CVE-2011-1585 affects Linux kernel versions before 2.6.36 and also impacts SUSE Linux Enterprise Server 10 SP4.
What are the potential impacts of exploiting CVE-2011-1585?
Exploiting CVE-2011-1585 allows local users to bypass CIFS share authentication, leading to unauthorized access to shared resources.
Is CVE-2011-1585 still a risk in modern Linux kernel versions?
CVE-2011-1585 is not a risk in modern Linux kernel versions as long as they are updated past version 2.6.36.