PT-2011-3683 · Linux+2 · Linux Kernel+2

·

CVE-2011-2213

·

Publicado

2011-07-15

·

Atualizado

2023-02-13

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.39.3
Description The issue is related to the inet diag bc audit function in the Linux kernel, which does not properly audit INET DIAG bytecode. This allows local users to cause a denial of service, specifically a kernel infinite loop, by sending crafted INET DIAG REQ BYTECODE instructions in a netlink message. For example, an INET DIAG BC JMP instruction with a zero yes value can trigger this issue.
Recommendations For Linux kernel versions prior to 2.6.39.3, update to version 2.6.39.3 or later to resolve the issue.

Correção

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2213
DSA-2310-1
DSA-2389-1
RHSA-2011:0927
RHSA-2011:1189
RHSA-2011:1253
RHSA-2011_0927
RHSA-2011_1189
USN-1203-1
USN-1208-1
USN-1216-1
USN-1218-1
USN-1219-1
USN-1220-1
USN-1225-1
USN-1227-1
USN-1228-1
USN-1241-1
USN-1246-1
USN-1256-1

Produtos afetados

Linux Kernel
Red Hat
Suse