CVE-2011-2213 REJECTED

The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.

EPSS 0.06% · 19.5th percentile

Risk Scores

EPSS Score
0.06%
19.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux0
Ubuntu:14.04:LTSlinux-flo0
Ubuntu:14.04:LTSlinux-goldfish0
Ubuntu:14.04:LTSlinux-grouper3.1.10-6.25, 0, 3.1.10-7.27
Ubuntu:14.04:LTSlinux-mako0
Ubuntu:14.04:LTSlinux-maguro0
Ubuntu:14.04:LTSlinux-manta0

Timeline

References

Open in Interactive Console →