PT-2011-4853 · Linux+3 · Linux Kernel+3
Petr Matousek
·
Publicado
2011-11-18
·
Atualizado
2023-02-13
·
CVE-2011-4132
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue is related to the Journaling Block Device (JBD) functionality in the Linux kernel, specifically the cleanup journal tail function. It allows local users to cause a denial of service, resulting in an assertion error and kernel oops, by using an ext3 or ext4 image with an invalid log first block value.
Recommendations
For Linux kernel version 2.6, consider restricting access to the JBD functionality until a patch is available. As a temporary workaround, avoid using the cleanup journal tail function with ext3 or ext4 images that may contain invalid log first block values.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat
Suse