Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade um-host-kernelUpgrade kernel-debugUpgrade kernel-umUpgrade kernel-symsUpgrade kernel-pmac64Upgrade kernel-64k-pagesizeUpgrade kernel-s390xUpgrade kernel-iseries64Upgrade kernel-sourceUpgrade kernel-smpUpgrade kernel-s390Upgrade kernel-pseries64Upgrade kernel-defaultUpgrade kernel-bigsmpUpgrade kernel-sn2Upgrade um-host-install-initrd | Feb 17, 2015 | Jan 10, 2005 |
| Ubuntu | — | Upgrade linux-image-2.6.8.1-3-power3-smpUpgrade linux-image-2.6.8.1-3-686-smpUpgrade linux-image-2.6.8.1-3-k7-smpUpgrade linux-image-2.6.8.1-3-amd64-k8Upgrade linux-image-2.6.8.1-3-amd64-xeonUpgrade linux-image-2.6.8.1-3-power4-smpUpgrade linux-image-2.6.8.1-3-386 | Nov 8, 2024 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub