Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23705
HistoryApr 10, 2020 - 12:34 a.m.

Denial Of Service (DoS)

2020-04-1000:34:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.115

Percentile

95.3%

kernel isvulnerable to denial of service (DoS). The vulnerability exists as several flaws were found in the way the Linux kernel CIFS implementation handles Unicode strings. CIFS clients convert Unicode strings sent by a server to their local character sets, and then write those strings into memory. If a malicious server sent a long enough string, it could write past the end of the target memory region and corrupt other memory areas, possibly leading to a denial of service or privilege escalation on the client mounting the CIFS share.

References