Description
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2389-1 | linux-2.6 security update |
EUVD |
EUVD-2011-4028 | Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname. |
Ubuntu USN |
USN-1291-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1292-1 | Linux kernel (Maverick backport) vulnerabilities |
Ubuntu USN |
USN-1293-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1299-1 | Linux kernel (EC2) vulnerabilities |
Ubuntu USN |
USN-1300-1 | Linux kernel (FSL-IMX51) vulnerabilities |
Ubuntu USN |
USN-1301-1 | Linux kernel (Natty backport) vulnerabilities |
Ubuntu USN |
USN-1302-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1303-1 | Linux kernel (Marvell DOVE) vulnerabilities |
Ubuntu USN |
USN-1304-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1311-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1312-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1330-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1336-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-1340-1 | Linux kernel (Oneiric backport) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T23:53:32.655Z
Reserved: 2011-10-18T00:00:00.000Z
Link: CVE-2011-4077
No data.
Status : Modified
Published: 2012-01-27T15:55:04.297
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-4077
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN