CVE-2011-1585
Publication date 6 October 2011
Last updated 24 July 2024
Ubuntu priority
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
From the Ubuntu Security Team
It was discovered that CIFS incorrectly handled authentication. When a user had a CIFS share mounted that required authentication, a local user could mount the same share without knowing the correct password.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | ||
linux-armadaxp | ||
linux-ec2 | ||
linux-fsl-imx51 | ||
linux-lts-backport-maverick | ||
linux-lts-backport-natty | ||
linux-lts-backport-oneiric | ||
linux-mvl-dove | ||
linux-ti-omap4 | ||
Patch details
Package | Patch details |
---|---|
linux |
References
Related Ubuntu Security Notices (USN)
- USN-1272-1
- Linux kernel vulnerabilities
- 21 November 2011
- USN-1280-1
- Linux (OMAP4) vulnerabilities
- 24 November 2011
- USN-1268-1
- Linux kernel vulnerabilities
- 21 November 2011
- USN-1203-1
- Linux kernel (Marvel DOVE) vulnerabilities
- 13 September 2011
- USN-1278-1
- Linux (Maverick backport) vulnerabilities
- 24 November 2011
- USN-1218-1
- Linux kernel vulnerabilities
- 29 September 2011
- USN-1208-1
- Linux kernel (Marvel DOVE) vulnerabilities
- 14 September 2011
- USN-1256-1
- Linux kernel (Natty backport) vulnerabilities
- 9 November 2011
- USN-1216-1
- Linux kernel (EC2) vulnerabilities
- 26 September 2011
- USN-1271-1
- Linux kernel (FSL-IMX51) vulnerabilities
- 21 November 2011