Back

MEDIUM

kernel: fuse: verify ioctl retries

Published Jun 21, 2012

Description

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit 59efec7b that introduced this issue. It did not affect the version of Linux kernel as shipped with Red hat Enterprise MRG as it did not provide support for Character device in Userspace (CUSE). A future kernel update in Red Hat Enterprise Linux 6 may address this flaw. Note that, by default, the "/dev/cuse" file in Red Hat Enterprise Linux 6 is only accessible by the root user.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 21, 2012
Updated Aug 7, 2024
Reserved Jan 3, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Nov 30, 2010