Back

LOW

samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE

Published Apr 10, 2011

Description

smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

Affected products

Remediation

Red Hat statement

On Red Hat Enterprise Linux, by default, mount.cifs is not provided with the setuid bit enabled. If a user has turned on the setuid bit (via chmod +s /sbin/mount.cifs), they would be affected by this issue, and can work around the problem by removing the setuid bit. Red Hat Enterprise Linux 3 does not provide the mount.cifs program.

Metrics

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2011
Updated Aug 6, 2024
Reserved Apr 9, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 3, 2011