On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer overflow. A NFS server that exports a cd9660, tarfs, or ext2fs file system can be made to panic by mounting and accessing the export with an NFS client. Further exploitation (e.g., bypassing file permission checking or remote kernel code execution) is potentially possible, though this has not been demonstrated. In particular, release kernels are compiled with stack protection enabled, and some instances of the overflow are caught by this mechanism, causing a panic.
History

Fri, 07 Feb 2025 17:45:00 +0000

Type Values Removed Values Added
References

Wed, 05 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 05:00:00 +0000

Type Values Removed Values Added
Description On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer overflow. A NFS server that exports a cd9660, tarfs, or ext2fs file system can be made to panic by mounting and accessing the export with an NFS client. Further exploitation (e.g., bypassing file permission checking or remote kernel code execution) is potentially possible, though this has not been demonstrated. In particular, release kernels are compiled with stack protection enabled, and some instances of the overflow are caught by this mechanism, causing a panic.
Title Buffer overflow in some filesystems via NFS
Weaknesses CWE-121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published: 2025-01-30T04:48:03.054Z

Updated: 2025-02-07T17:02:45.863Z

Reserved: 2025-01-10T08:47:56.804Z

Link: CVE-2025-0373

cve-icon Vulnrichment

Updated: 2025-02-07T17:02:45.863Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-30T05:15:09.590

Modified: 2025-02-07T17:15:30.760

Link: CVE-2025-0373

cve-icon Redhat

No data.