PT-2011-1039 · Linux+1 · Libcgroup-Debuginfo+4
Jan Lieskovsky
·
Published
2011-03-03
·
Updated
2011-09-07
·
CVE-2011-1022
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libcgroup versions prior to 0.37.1
libcgroup-pam version 0.36.1
libcgroup-devel version 0.36.1
libcgroup-debuginfo version 0.36.1
Description
The issue concerns multiple vulnerabilities in the libcgroup package, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally, allowing attackers to bypass intended resource restrictions. The
cgre receive netlink msg function in daemon/cgrulesengd.c does not verify that netlink messages originated in the kernel, enabling local users to exploit this weakness via crafted messages.Recommendations
For versions prior to 0.37.1, update to version 0.37.1 or later to resolve the issue.
For libcgroup-pam version 0.36.1, update to a version that includes the fix for this vulnerability.
For libcgroup-devel version 0.36.1, update to a version that includes the fix for this vulnerability.
For libcgroup-debuginfo version 0.36.1, update to a version that includes the fix for this vulnerability.
As a temporary workaround, consider restricting access to the
cgre receive netlink msg function until a patch is available.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Libcgroup
Libcgroup-Debuginfo
Libcgroup-Devel
Libcgroup-Pam