PT-2013-1402 · Linux+1 · Linux Kernel+1

CVE-2011-2942

·

Published

2011-10-20

·

Updated

2023-02-13

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6.18 on Red Hat Enterprise Linux (RHEL) 5
Description The issue is related to a certain Red Hat patch to the br deliver function in net/bridge/br forward.c in the Linux kernel. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and system crash, or possibly have other unspecified impacts. The attack can be leveraged by connecting to a network interface that uses an Ethernet bridge device.
Recommendations For Linux kernel version 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, consider applying a patch to fix the issue in the br deliver function. As a temporary workaround, restrict access to network interfaces that use Ethernet bridge devices to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-2942
RHSA-2011:1386
RHSA-2011_1386

Affected Products

Linux Kernel
Red Hat