PT-2011-1044 · Debian+2 · Debian+2

Eugene Teo

·

Published

2011-03-02

·

Updated

2023-02-13

·

CVE-2011-2189

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6.32 and earlier
Description The issue is related to the handling of network namespaces in the Linux kernel. It does not properly handle a high rate of creation and cleanup of these namespaces, which can lead to a denial of service due to memory consumption. This can be exploited by remote attackers through requests to a daemon that requires a separate namespace per connection. An example of such a daemon is vsftpd. Additionally, there are multiple vulnerabilities in the vsftpd package in Debian GNU/Linux that can lead to disruption of protected information, and these can be exploited remotely.
Recommendations For Linux kernel version 2.6.32 and earlier, consider upgrading to a newer version to mitigate the risk of denial of service attacks. As a temporary workaround, consider restricting access to daemons that require a separate namespace per connection, such as vsftpd, to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2015-02948
CVE-2011-2189

Affected Products

Debian
Linux Kernel
Vsftpd