PT-2011-4849 · Linux+2 · Linux Kernel+2

David Howells

·

Published

2011-11-23

·

Updated

2023-02-13

·

CVE-2011-4110

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6
Description The issue is related to the user update function in the Linux kernel, which allows local users to cause a denial of service. This can be achieved through vectors related to a user-defined key and updating a negative key into a fully instantiated key, resulting in a NULL pointer dereference and kernel oops.
Recommendations For Linux kernel version 2.6, as a temporary workaround, consider disabling the user update function until a patch is available. Restrict access to the security/keys/user defined.c module to minimize the risk of exploitation. Avoid using the user defined key in the affected kernel version until the issue is resolved.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2011-4110
DSA-2389-1
RHSA-2011:1479
RHSA-2011:1530
RHSA-2011_1479
RHSA-2011_1530
RHSA-2012:0010
RHSA-2012:0116
RHSA-2012:0333
USN-1318-1
USN-1319-1
USN-1322-1
USN-1323-1
USN-1324-1
USN-1325-1
USN-1328-1
USN-1330-1
USN-1332-1
USN-1336-1
USN-1337-1
USN-1340-1
USN-1341-1
USN-1344-1
USN-1345-1

Affected Products

Linux Kernel
Red Hat
Suse