PT-2011-1076 · Linux+1 · Linux Kernel+1
Robert Swiecki
·
Published
2011-03-01
·
Updated
2023-02-13
·
CVE-2011-1593
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.38.4
Description
The issue is related to multiple integer overflows in the next pidmap function in kernel/pid.c, which can cause a denial of service (system crash) via crafted system calls, specifically (1) getdents or (2) readdir. Additionally, there are multiple vulnerabilities in the kernel-kdumppae package of SUSE Linux Enterprise that can lead to disruption of protected information availability, and these can be exploited remotely.
Recommendations
For Linux kernel versions prior to 2.6.38.4, update to version 2.6.38.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
next pidmap function in kernel/pid.c to minimize the risk of exploitation.
Avoid using the getdents and readdir system calls in the affected kernel versions until the issue is resolved.Exploit
Fix
DoS
RCE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat