PT-2011-1039 · Linux+1 · Libcgroup-Debuginfo+4

Jan Lieskovsky

·

Published

2011-03-03

·

Updated

2011-09-07

·

CVE-2011-1022

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libcgroup versions prior to 0.37.1 libcgroup-pam version 0.36.1 libcgroup-devel version 0.36.1 libcgroup-debuginfo version 0.36.1
Description The issue concerns multiple vulnerabilities in the libcgroup package, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally, allowing attackers to bypass intended resource restrictions. The cgre receive netlink msg function in daemon/cgrulesengd.c does not verify that netlink messages originated in the kernel, enabling local users to exploit this weakness via crafted messages.
Recommendations For versions prior to 0.37.1, update to version 0.37.1 or later to resolve the issue. For libcgroup-pam version 0.36.1, update to a version that includes the fix for this vulnerability. For libcgroup-devel version 0.36.1, update to a version that includes the fix for this vulnerability. For libcgroup-debuginfo version 0.36.1, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the cgre receive netlink msg function until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02876
BDU:2015-05991
BDU:2015-05992
BDU:2015-05993
BDU:2015-05994
CVE-2011-1022
DSA-2193-1
OPENSUSE-SU-2024:10391-1
RHSA-2011:0320
RHSA-2011_0320

Affected Products

Red Hat
Libcgroup
Libcgroup-Debuginfo
Libcgroup-Devel
Libcgroup-Pam