CVE-2011-0714
published 2011-05-04CVE-2011-0714: Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL)…
PriorityP419medium5.7CVSS 2.0
AVAACMAuNCNINAC
EPSS
0.95%
57.2th percentile
Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-38jw-wfq7-q7m7: Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2
ghsa_unreviewed·2022-05-14
CVE-2011-0714 [MEDIUM] GHSA-38jw-wfq7-q7m7: Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2
Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.
Red Hat
kernel: deficiency in handling of invalid data packets in lockd
vendor_redhat·2011-03-08·CVSS 5.7
CVE-2011-0714 [MEDIUM] kernel: deficiency in handling of invalid data packets in lockd
kernel: deficiency in handling of invalid data packets in lockd
Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.
Statement: This issue only affects Red Hat Enterprise Linux 6 as we did not properly backport upstream commit b48fa6b9. The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG are not affected.
Package: kernel-rt (Red Hat Enterprise MRG 1) - Affected
No detection rules found.
No public exploits indexed.
http://openwall.com/lists/oss-security/2011/03/08/17http://openwall.com/lists/oss-security/2011/03/09/1https://bugzilla.redhat.com/show_bug.cgi?id=678144https://rhn.redhat.com/errata/RHSA-2011-0329.htmlhttp://openwall.com/lists/oss-security/2011/03/08/17http://openwall.com/lists/oss-security/2011/03/09/1https://bugzilla.redhat.com/show_bug.cgi?id=678144https://rhn.redhat.com/errata/RHSA-2011-0329.html
2011-05-04
Published