imPC@ndo EN

Tracker / CVE-2011-2213

CVE-2011-2213

Media 4.9

The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.

Prodotti e versioni affette

linux linux_kernel · … → 2.6.39.3
redhat enterprise_linux_aus
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_server
redhat enterprise_linux_workstation

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti