PT-2012-1861 · Linux+1 · Linux Kernel+1
Eugene Teo
·
Published
2012-01-10
·
Updated
2023-02-13
·
CVE-2011-4325
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.31-rc6
Description
The issue is related to the NFS implementation in the Linux kernel, where certain functions are called without properly initializing specific data. This can be exploited by local users to cause a denial of service, resulting in a NULL pointer dereference and O DIRECT oops. An example of exploitation is demonstrated using the diotest4 test from the LTP suite.
Recommendations
For Linux kernel versions prior to 2.6.31-rc6, update to version 2.6.31-rc6 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat