UBUNTU-CVE-2012-2375
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 13 Jun 2012, 00:00
Last modified:04 Feb 2026, 02:47
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Jun 2012, 00:00
Published
Vulnerability first disclosed
04 Feb 2026, 02:47
Last Modified
Vulnerability information updated
Description
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
Affected Systems
- ubuntu•linux
< 3.11.0-12.19
- ubuntu•linux-flo
< 3.4.0-1.3
- ubuntu•linux-goldfish
< 3.4.0-1.9
- ubuntu•linux-mako
< 3.4.0-3.21
- ubuntu•linux-manta
< 3.4.0-4.19
References (11)
- https://ubuntu.com/security/CVE-2012-2375
- http://www.openwall.com/lists/oss-security/2012/05/18/13
- https://ubuntu.com/security/notices/USN-1486-1
- https://ubuntu.com/security/notices/USN-1487-1
- https://ubuntu.com/security/notices/USN-1488-1
- https://ubuntu.com/security/notices/USN-1489-1
- https://ubuntu.com/security/notices/USN-1490-1
- https://ubuntu.com/security/notices/USN-1494-1
- https://ubuntu.com/security/notices/USN-1499-1
- https://ubuntu.com/security/notices/USN-1530-1
- https://www.cve.org/CVERecord?id=CVE-2012-2375