Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's CIFS (Common Internet File System) implementation for SMB1 UNIX mounts has been addressed. The issue arose because the CIFS mount context flags were not properly updated before resetting UNIX capabilities, leading to the absence of crucial POSIX-related flags. This omission caused incorrect directory separators in file paths. The vulnerability affected several versions of the Linux kernel that are part of the stable release.
The vulnerability could lead to incorrect handling of file paths in SMB1 UNIX mounts, potentially causing applications to misinterpret directory structures or file locations.
Users can upgrade to the latest version of the Linux kernel to address this vulnerability. The patched version is included in the official Linux kernel stable releases.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.