CVE-2011-0714Kernel vulnerability

CWE-3994 documents4 sources
Severity
5.7MEDIUMNVD
EPSS
0.3%
top 46.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 14

Description

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.

CVSS vector

AV:A/AC:M/C:N/I:N/A:CExploitability: 5.5 | Impact: 6.9

Affected Packages1 packages

NVDlinux/linux_kernel2.6.32

Also affects: Enterprise Linux 6.0

🔴Vulnerability Details

1
GHSA
GHSA-38jw-wfq7-q7m7: Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 22022-05-14

📋Vendor Advisories

1
Red Hat
kernel: deficiency in handling of invalid data packets in lockd2011-03-08

💬Community

1
Bugzilla
CVE-2011-0714 kernel: deficiency in handling of invalid data packets in lockd2011-02-16