CVE-2011-0695Race Condition in Kernel

Severity
5.7MEDIUMNVD
EPSS
0.4%
top 36.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 13

Description

Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.

CVSS vector

AV:A/AC:M/C:N/I:N/A:CExploitability: 5.5 | Impact: 6.9

Affected Packages4 packages

Also affects: Ubuntu Linux 8.04, Enterprise Linux 5.6

Patches

🔴Vulnerability Details

1
GHSA
GHSA-297p-pfx7-4599: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma2022-05-13

📋Vendor Advisories

9
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (Marvell Dove)2011-07-13
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06
Ubuntu
Linux kernel vulnerabilities2011-06-28

📐Framework References

1
CWE
Improper Update of Reference Count

💬Community

1
Bugzilla
CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler2010-11-15