CVE-2011-2928
MEDIUM 4.9EPSS 0.5%
The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long symlink on a malformed Be filesystem.
- CVSS v2.0
- 4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C - EPSS
- 0.51% chance of exploitation in the next 30 days, 41th percentile
- Published
- 2011-08-29
- Updated
- 2024-08-06