PT-2011-1044 · Debian+2 · Debian+2
Eugene Teo
·
Published
2011-03-02
·
Updated
2023-02-13
·
CVE-2011-2189
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6.32 and earlier
Description
The issue is related to the handling of network namespaces in the Linux kernel. It does not properly handle a high rate of creation and cleanup of these namespaces, which can lead to a denial of service due to memory consumption. This can be exploited by remote attackers through requests to a daemon that requires a separate namespace per connection. An example of such a daemon is vsftpd. Additionally, there are multiple vulnerabilities in the vsftpd package in Debian GNU/Linux that can lead to disruption of protected information, and these can be exploited remotely.
Recommendations
For Linux kernel version 2.6.32 and earlier, consider upgrading to a newer version to mitigate the risk of denial of service attacks.
As a temporary workaround, consider restricting access to daemons that require a separate namespace per connection, such as vsftpd, to minimize the risk of exploitation.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linux Kernel
Vsftpd