PT-2011-4853 · Linux+3 · Linux Kernel+3

Petr Matousek

·

Published

2011-11-18

·

Updated

2023-02-13

·

CVE-2011-4132

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6
Description The issue is related to the Journaling Block Device (JBD) functionality in the Linux kernel, specifically the cleanup journal tail function. It allows local users to cause a denial of service, resulting in an assertion error and kernel oops, by using an ext3 or ext4 image with an invalid log first block value.
Recommendations For Linux kernel version 2.6, consider restricting access to the JBD functionality until a patch is available. As a temporary workaround, avoid using the cleanup journal tail function with ext3 or ext4 images that may contain invalid log first block values.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0350
CVE-2011-4132
ELSA-2012-0350
ELSA-2012-2003
RHSA-2012:0007
RHSA-2012:0010
RHSA-2012:0333
RHSA-2012:0350
RHSA-2012_0007
RHSA-2012_0350
USN-1286-1
USN-1291-1
USN-1292-1
USN-1293-1
USN-1299-1
USN-1300-1
USN-1301-1
USN-1302-1
USN-1303-1
USN-1304-1
USN-1311-1
USN-1312-1
USN-1322-1
USN-1330-1
USN-1336-1
USN-1340-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse