Linux_Kernel_nfsd_Subsystem_Buffer_Overflow_attack

Strike ID:
G08-60r01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2008

Description

A remote denial of service vulnerability exists in the Linux Kernel. The vulnerability is due to an implementation flaw which may result in a buffer overflow in the NFS subsystem of the Linux Kernel. By sending Access Control List (ACL) NFS requests to a target host, an attacker may exploit this vulnerability to cause kernel panic, leading to a system wide denial of service condition. Exploiting this vulnerability successfully will cause a kernel panic condition on the target system. The kernel will log a panic message on the system console containing debug information pertaining to the panic condition which includes the call trace, register values and so on. The target host must be restarted to resume its functionality.

CVE

References

Bid