First published: Thu Sep 08 2011(Updated: )
Buffer overflow in the fuse_notify_inval_entry function in fs/fuse/dev.c in the Linux kernel before 3.1 allows local users to cause a denial of service (BUG_ON and system crash) by leveraging the ability to mount a FUSE filesystem.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux kernel | <3.1 | |
Linux Kernel | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3353 has a severity rating that can lead to denial of service causing system crashes.
To fix CVE-2011-3353, ensure you are using a Linux kernel version 3.1 or higher that addresses the buffer overflow vulnerability.
Local users on systems running Linux kernels prior to version 3.1 that support FUSE are affected by CVE-2011-3353.
CVE-2011-3353 can lead to a denial of service condition resulting in system crashes due to improper handling of the FUSE_NOTIFY_INVAL_ENTRY.
No, CVE-2011-3353 is a local vulnerability that requires local user access to exploit.