CVE-2011-2203
Published: 2 December 2011
The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record.
From the Ubuntu security team
Clement Lecigne discovered a bug in the HFS filesystem. A local attacker could exploit this to cause a kernel oops.
Priority
Status
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2203
- https://rhn.redhat.com/errata/RHSA-2011-1465.html
- https://lkml.org/lkml/2011/6/8/154
- https://ubuntu.com/security/notices/USN-1318-1
- https://ubuntu.com/security/notices/USN-1319-1
- https://ubuntu.com/security/notices/USN-1322-1
- https://ubuntu.com/security/notices/USN-1323-1
- https://ubuntu.com/security/notices/USN-1325-1
- https://ubuntu.com/security/notices/USN-1324-1
- https://ubuntu.com/security/notices/USN-1328-1
- https://ubuntu.com/security/notices/USN-1330-1
- https://ubuntu.com/security/notices/USN-1332-1
- https://ubuntu.com/security/notices/USN-1337-1
- https://ubuntu.com/security/notices/USN-1340-1
- https://ubuntu.com/security/notices/USN-1341-1
- https://ubuntu.com/security/notices/USN-1344-1
- https://ubuntu.com/security/notices/USN-1345-1
- https://ubuntu.com/security/notices/USN-1336-1
- NVD
- Launchpad
- Debian