PT-2011-4849 · Linux+2 · Linux Kernel+2
David Howells
·
Publicado
2011-11-23
·
Atualizado
2023-02-13
·
CVE-2011-4110
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue is related to the
user update function in the Linux kernel, which allows local users to cause a denial of service. This can be achieved through vectors related to a user-defined key and updating a negative key into a fully instantiated key, resulting in a NULL pointer dereference and kernel oops.Recommendations
For Linux kernel version 2.6, as a temporary workaround, consider disabling the
user update function until a patch is available. Restrict access to the security/keys/user defined.c module to minimize the risk of exploitation. Avoid using the user defined key in the affected kernel version until the issue is resolved.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Suse