CVE-2011-2517Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel

Severity
7.2HIGHNVD
EPSS
0.1%
top 69.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 13

Description

Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages5 packages

Also affects: Enterprise Linux 5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7m92-7xrw-x2p7: Multiple buffer overflows in net/wireless/nl802112022-05-13
OSV
CVE-2011-2517: Multiple buffer overflows in net/wireless/nl802112011-10-06

📋Vendor Advisories

11
Ubuntu
Linux kernel vulnerabilities2011-12-03
Ubuntu
Linux kernel vulnerabilities2011-11-29
Ubuntu
Linux (Maverick backport) vulnerabilities2011-11-24
Ubuntu
Linux (Natty backport) vulnerabilities2011-11-24
Ubuntu
Linux (OMAP4) vulnerabilities2011-11-24

💬Community

1
Bugzilla
CVE-2011-2517 kernel: nl80211: missing check for valid SSID size in scan operations2011-07-01