CVE-2011-4110
kernel: keys: NULL pointer deref in the user-defined key type
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."
La función user_update security/keys/user_defined.c en el kernel de Linux v2.6 permite a usuarios locales provocar una denegación de servicio (desreferencia de puntero a NULL y fallo del kernel) a través de vectores relacionados con una clave definida por el usuario y la "actualización de una clave negativa en una clave completamente instanciada".
Potential vulnerabilities have been identified with HP Rapid Deployment Pack (RDP) or HP Insight Control Server Deployment. The vulnerabilities could be exploited remotely affecting confidentiality, integrity and availability. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-10-18 CVE Reserved
- 2012-01-27 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-476: NULL Pointer Dereference
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/47754 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2011/11/21/19 | Mailing List | |
http://www.openwall.com/lists/oss-security/2011/11/22/5 | Mailing List | |
http://www.openwall.com/lists/oss-security/2011/11/22/6 | Mailing List | |
http://www.securityfocus.com/bid/50755 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://lkml.org/lkml/2011/11/15/363 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=751297 | 2012-02-23 |
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=139447903326211&w=2 | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-1324-1 | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-1328-1 | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-1344-1 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2011-4110 | 2012-02-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6 Search vendor "Linux" for product "Linux Kernel" and version "2.6" | - |
Affected
|