PT-2011-3683 · Linux+2 · Linux Kernel+2

Dan Rosenberg

·

Published

2011-07-15

·

Updated

2023-02-13

·

CVE-2011-2213

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.39.3
Description The issue is related to the inet diag bc audit function in the Linux kernel, which does not properly audit INET DIAG bytecode. This allows local users to cause a denial of service, specifically a kernel infinite loop, by sending crafted INET DIAG REQ BYTECODE instructions in a netlink message. For example, an INET DIAG BC JMP instruction with a zero yes value can trigger this issue.
Recommendations For Linux kernel versions prior to 2.6.39.3, update to version 2.6.39.3 or later to resolve the issue.

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2011-2213
DSA-2310-1
DSA-2389-1
RHSA-2011:0927
RHSA-2011:1189
RHSA-2011:1253
RHSA-2011_0927
RHSA-2011_1189
USN-1203-1
USN-1208-1
USN-1216-1
USN-1218-1
USN-1219-1
USN-1220-1
USN-1225-1
USN-1227-1
USN-1228-1
USN-1241-1
USN-1246-1
USN-1256-1

Affected Products

Linux Kernel
Red Hat
Suse