Security Advisory

CVE-2011-2928

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-08-29 17:00:00
Last updated 2024-08-06 23:15:31
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long symlink on a malformed Be filesystem.