PT-2011-4853 · Linux+3 · Linux Kernel+3
Petr Matousek
·
Published
2011-11-18
·
Updated
2023-02-13
·
CVE-2011-4132
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue is related to the Journaling Block Device (JBD) functionality in the Linux kernel, specifically the cleanup journal tail function. It allows local users to cause a denial of service, resulting in an assertion error and kernel oops, by using an ext3 or ext4 image with an invalid log first block value.
Recommendations
For Linux kernel version 2.6, consider restricting access to the JBD functionality until a patch is available. As a temporary workaround, avoid using the cleanup journal tail function with ext3 or ext4 images that may contain invalid log first block values.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat
Suse