Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2525

Опубликовано: 21 мая 2010
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.

Отчет

This flaw affects Red Hat Enterprise Linux 4 and 5. It did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they have already backported the upstream commit 53b0f080 that addressed this flaw. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1065.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelWill not fix
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux Extended Update Support 5.6kernelAffected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 5kernelFixedRHSA-2011:106521.07.2011
Red Hat Enterprise Linux 5kernelFixedRHSA-2011:116316.08.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=720552kernel: kernel: net_sched: fix qdisc_notify()

EPSS

Процентиль: 29%
0.00103
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 13 лет назад

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.

CVSS3: 7.8
nvd
больше 13 лет назад

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.

CVSS3: 7.8
debian
больше 13 лет назад

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel b ...

CVSS3: 7.8
github
около 3 лет назад

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.

oracle-oval
почти 14 лет назад

ELSA-2011-1065: Oracle Linux 5.7 kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 29%
0.00103
Низкий

4.9 Medium

CVSS2