Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
- http://marc.info/?l=bugtraq&m=105950927708272&w=2
- http://www.redhat.com/support/errata/RHSA-2003-239.html
No PoCs found on GitHub currently.