CVE-2011-1093

Severity
7.8HIGH
EPSS
1.2%
top 20.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 13

Description

The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages4 packages

Also affects: Enterprise Linux 5.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rf9x-2w4m-rh77: The dccp_rcv_state_process function in net/dccp/input2022-05-13
CVEList
CVE-2011-1093: The dccp_rcv_state_process function in net/dccp/input2011-07-18

📋Vendor Advisories

10
Ubuntu
Linux kernel (Natty backport) vulnerabilities2011-11-09
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel (i.MX51) vulnerabilities2011-09-13
Ubuntu
Linux kernel vulnerabilities2011-08-19
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09

💬Community

1
Bugzilla
CVE-2011-1093 kernel: dccp: fix oops on Reset after close2011-03-08
CVE-2011-1093 (HIGH CVSS 7.8) | The dccp_rcv_state_process function | cvebase.io