Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel CIFS DNS解析功能设计错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 2.6.35之前版本中的CIFS工具中的DNS解析功能在启用CONFIG_CIFS_DFS_UPCALL时,没有对cifs.upcall的用户空间辅助dns_resolver upcall的用户密钥环进行正确的访问限制,本地用户可以借助包含add_key调用的向量欺骗DNS查询请求结果和执行任意CIFS加载。
CVSS Information
N/A
Vulnerability Type
N/A