PT-2011-1062 · Suse+2 · Ext4Dev-Kmp-Trace+4

Ryan Sweat

·

Publicado

2011-04-08

·

Atualizado

2023-02-13

·

CVE-2011-1478

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.38
Description The issue is related to the Generic Receive Offload (GRO) implementation in the Linux kernel. A problem in the napi reuse skb function in net/core/dev.c does not reset the values of certain structure members. This could allow remote attackers to cause a denial of service, specifically a NULL pointer dereference, by manipulating a VLAN frame. Additionally, there are multiple vulnerabilities in the ext4dev-kmp-trace package of the SUSE Linux Enterprise operating system that can lead to disruption of protected information availability, potentially exploitable remotely.
Recommendations For Linux kernel versions prior to 2.6.38, update to version 2.6.38 or later to resolve the issue. At the moment, there is no information about a newer version that contains a fix for the ext4dev-kmp-trace package vulnerabilities in the SUSE Linux Enterprise operating system.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04359
CVE-2011-1478
DSA-2240-1
RHSA-2011:0421
RHSA-2011:0429
RHSA-2011:1253
RHSA-2011_0421
RHSA-2011_0429

Produtos afetados

Linux Kernel
Red Hat
Suse Linux Enterprise
Suse
Ext4Dev-Kmp-Trace