CVE-2011-3191: Buffer Overflow
Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
Other sources
The namelen variable in CIFSFindNext is a signed int that gets set to the resumenamelen in the cifssearchinfo. The resumenamelen however is unsigned and for some infolevels is populated directly from a 32 bit value sent by the server.
If the server sends a very large value for this, then that value could look negative when converted to a signed int. That would make that value pass the PATHMAX check later in CIFSFindNext. The namelen would then be used as a length value for a memcpy. It would then be treated as unsigned again, and the memcpy scribbles over a ton of memory.
Fix this by making the namelen an unsigned value in CIFSFindNext.
http://www.spinics.net/lists/linux-cifs/msg03950.html
Acknowledgements:
Red Hat would like to thank Darren Lavender for reporting this issue.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3191?
CVE-2011-3191 is rated as a high severity vulnerability due to its potential for causing denial of service and memory corruption.
How do I fix CVE-2011-3191?
To fix CVE-2011-3191, upgrade your Linux kernel to version 3.1 or newer, which includes the necessary patches.
Which Linux kernel versions are affected by CVE-2011-3191?
CVE-2011-3191 affects Linux kernel versions before 3.1, specifically versions prior to 3.0.5.
What types of attacks can exploit CVE-2011-3191?
CVE-2011-3191 can be exploited by remote CIFS servers sending a large length value in a directory read request, leading to potential memory corruption.
Are there any specific distributions known to be affected by CVE-2011-3191?
Yes, Red Hat Enterprise Linux version 4.0 and various versions of Debian's linux-2.6 are known to be affected by CVE-2011-3191.