The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unspecified other impact via a NULL value for the device name.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-2.6.38-13-serverUpgrade linux-image-2.6.38-13-virtualUpgrade linux-image-2.6.38-13-generic-paeUpgrade linux-image-2.6.38-13-versatileUpgrade linux-image-2.6.38-13-powerpcUpgrade linux-image-2.6.38-1209-omap4Upgrade linux-image-2.6.38-13-genericUpgrade linux-image-2.6.38-13-powerpc64-smpUpgrade linux-image-2.6.38-13-omapUpgrade linux-image-2.6.38-13-powerpc-smp | Nov 8, 2024 | May 24, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub