CIFSFindNext Function Integer Signedness Error Vulnerability

CIFSFindNext Function Integer Signedness Error Vulnerability

CVE-2011-3191 · HIGH Severity

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.