CVE-2011-1182

12 documents6 sources
Severity
3.6LOW
EPSS
0.1%
top 76.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 13

Description

kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.

CVSS vector

AV:L/AC:L/C:N/I:P/A:PExploitability: 3.9 | Impact: 4.9

Affected Packages4 packages

Also affects: Enterprise Linux 5.0, 5.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r2p8-xfjx-qrfg: kernel/signal2022-05-13
CVEList
CVE-2011-1182: kernel/signal2013-03-01

📋Vendor Advisories

8
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-21
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (Marvell Dove)2011-07-13
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06

💬Community

1
Bugzilla
CVE-2011-1182 kernel signal spoofing issue2011-03-23
CVE-2011-1182 (LOW CVSS 3.6) | kernel/signal.c in the Linux kernel | cvebase.io