PT-2011-4849 · Linux+2 · Linux Kernel+2
David Howells
·
Published
2011-11-23
·
Updated
2023-02-13
·
CVE-2011-4110
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue is related to the
user update function in the Linux kernel, which allows local users to cause a denial of service. This can be achieved through vectors related to a user-defined key and updating a negative key into a fully instantiated key, resulting in a NULL pointer dereference and kernel oops.Recommendations
For Linux kernel version 2.6, as a temporary workaround, consider disabling the
user update function until a patch is available. Restrict access to the security/keys/user defined.c module to minimize the risk of exploitation. Avoid using the user defined key in the affected kernel version until the issue is resolved.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Suse