CVE-2012-1090

Published: 28 February 2012

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO. "The cifs code will attempt to open files on lookup under certain circumstances. What happens though if we find that the file we opened was actually a FIFO or other special file? Currently, the open filehandle just ends up being leaked leading to a dentry refcount mismatch and oops on umount."

From the Ubuntu security team

A flaw was discovered in the Linux kernel's cifs file system. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service.

Priority

Low

CVSS 3 base score: 5.5

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
Patches:
Introduced by 8db14ca12569fe885694bd3d5ff84c2d973d3cb0
Fixed by 5bccda0ebc7c0331b81ac47d39e4b920b198b2cd
linux-armadaxp
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-ec2
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-backport-maverick
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-backport-natty
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-backport-oneiric
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-quantal
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-raring
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-mvl-dove
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)
linux-ti-omap4
Launchpad, Ubuntu, Debian
Upstream
Released (3.3~rc7)