CVE-2011-4077

Public on 2011-11-19
Modified on 2014-09-14
Description
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel 2011-11-19 ALAS-2011-22 Fixed
Amazon Linux 1 kernel 2012-03-16 ALAS-2012-55 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 6.2 AV:L/AC:H/Au:N/C:C/I:C/A:C
NVD CVSSv2 6.9 AV:L/AC:M/Au:N/C:C/I:C/A:C