PT-2012-1861 · Linux+1 · Linux Kernel+1

Eugene Teo

·

Published

2012-01-10

·

Updated

2023-02-13

·

CVE-2011-4325

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.31-rc6
Description The issue is related to the NFS implementation in the Linux kernel, where certain functions are called without properly initializing specific data. This can be exploited by local users to cause a denial of service, resulting in a NULL pointer dereference and O DIRECT oops. An example of exploitation is demonstrated using the diotest4 test from the LTP suite.
Recommendations For Linux kernel versions prior to 2.6.31-rc6, update to version 2.6.31-rc6 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-4325
RHSA-2012:0007
RHSA-2012_0007

Affected Products

Linux Kernel
Red Hat