LWN.net Logo

kernel: vulnerabilities in the smb file system

Package(s):kernel CVE #(s):CAN-2004-0883 CAN-2004-0949
Created:November 19, 2004 Updated:December 14, 2004
Description: During an audit of the smb file system implementation within Linux, several vulnerabilities were discovered ranging from out of bounds read accesses to kernel level buffer overflows. See these advisories: Linux kernel binfmt_elf loader vulnerabilities and Memory leak in 2.4.27 kernel for more information.
Alerts:
Red Hat RHSA-2004:504-01 2004-12-13
Red Hat RHSA-2004:505-01 2004-12-13
Red Hat RHSA-2004:549-01 2004-12-02
SuSE SUSE-SA:2004:042 2004-12-01
Ubuntu USN-30-1 2004-11-18

(Log in to post comments)

kernel: vulnerabilities in the smb file system

Posted Dec 16, 2004 13:53 UTC (Thu) by stevef (subscriber, #7712) [Link]

At least for 2.6, smbfs is obsolete for all but two cases (kerberos negotiation and OS/2 servers), replaced by cifs filesystem. If I could track down the patch I can code/review the smbfs patch for 2.6

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds