CVE-2011-1082
Linux Kernel 2.6.x - fs/eventpoll.c epoll Data Structure File Descriptor Local Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
fs/eventpoll.c en el kernel de Linux anterior a v2.6.38 coloca descriptores de fichero epoll dentro de otra estructura de datos epoll sin comprobar correctamente para (1) bucles cerrados (2) profundidad de cadena, lo que permite a usuarios locales provocar una denegación de servicio (bloqueo o agotamiento de la pila de memoria) a través de una aplicación que hace epoll_create y llamadas al sistema epoll_ctl.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-02-24 CVE Reserved
- 2011-03-02 First Exploit
- 2011-04-03 CVE Published
- 2024-01-10 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e | X_refsource_confirm | |
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35404 | 2011-03-02 |
URL | Date | SRC |
---|---|---|
http://openwall.com/lists/oss-security/2011/03/02/1 | 2023-02-13 | |
http://openwall.com/lists/oss-security/2011/03/02/2 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=681575 | 2011-06-21 | |
https://lkml.org/lkml/2011/2/5/220 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2011-1082 | 2011-06-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 2.6.38 Search vendor "Linux" for product "Linux Kernel" and version " < 2.6.38" | - |
Affected
|