CVE-2011-3191

NameCVE-2011-3191
DescriptionInteger signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2303-1, DSA-2310-1
NVD severityhigh (attack range: remote)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linux-2.6source(unstable)3.0.0-5high
linux-2.6sourcelenny2.6.26-26lenny4highDSA-2310-1
linux-2.6sourcesqueeze2.6.32-35squeeze1highDSA-2303-1

Search for package or bug name: Reporting problems