CVE-2011-2525
published 2012-02-02CVE-2011-2525: The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka…
PriorityP428high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.50%
39.3th percentile
The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 2.6.35 | 2.6.35 |
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hrf-7c2r-c5x7: The qdisc_notify function in net/sched/sch_api
ghsa_unreviewed·2022-05-13
CVE-2011-2525 [HIGH] CWE-476 GHSA-4hrf-7c2r-c5x7: The qdisc_notify function in net/sched/sch_api
The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
OSV
CVE-2011-2525: The qdisc_notify function in net/sched/sch_api
osv·2011-10-06·CVSS 7.8
CVE-2011-2525 [HIGH] CVE-2011-2525: The qdisc_notify function in net/sched/sch_api
The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-12-03·CVSS 4.9
CVE-2011-2491 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause a
denial of service. (CVE-2011-2491)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A local attacker could exploit this to crash the system, leading to a
denial of service. (CVE-2011-2496)
It was discovered that the wireless stack incorrectly verified SSID
lengths. A local attacker could exploit this to cause a denial of service
or gain root privileges. (CVE-2011-2517)
Ben Pfaff discovered that Classless Queuing Disciplines (qdiscs) were being
incorrectly handled. A local attacker could exploit this to crash the
system, leadin
Ubuntu
Linux kernel (Marvell DOVE) vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 4.9
CVE-2011-2491 [MEDIUM] Linux kernel (Marvell DOVE) vulnerabilities
Title: Linux kernel (Marvell DOVE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause a
denial of service. (CVE-2011-2491)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A local attacker could exploit this to crash the system, leading to a
denial of service. (CVE-2011-2496)
It was discovered that the wireless stack incorrectly verified SSID
lengths. A local attacker could exploit this to cause a denial of service
or gain root privileges. (CVE-2011-2517)
Ben Pfaff discovered that Classless Queuing Disciplines (qdiscs) were being
incorrectly handled. A local attacker could exploit this to crash the
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 4.9
CVE-2011-2525 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause a
denial of service. (CVE-2011-2491)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A local attacker could exploit this to crash the system, leading to a
denial of service. (CVE-2011-2496)
It was discovered that the wireless stack incorrectly verified SSID
lengths. A local attacker could exploit this to cause a denial of service
or gain root privileges. (CVE-2011-2517)
Ben Pfaff discovered that Classless Queuing Disciplines (qdiscs) were being
incorrectly handled. A local attacker could exploit this to crash the
system,
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 3.3
CVE-2011-1585 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
It was discovered that the GRE protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ip_gre
module was loading, and crash the system, leading to a denial of service.
(CVE-2011-1767)
It was discovered that the IP/IP protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ipip module
was loading, and crash the system, leading to a denial of service.
(CVE-2011-1768)
Vasily Averin discove
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-11-09·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear
memory. A local attacker could exploit this to read kernel stack memory,
leading to a loss of privacy. (CVE-2011-1078)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check
that device name strings were NULL terminated. A local attacker could
exploit this to crash the system,
Ubuntu
Linux kernel (i.MX51) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 5.9
CVE-2011-1573 [MEDIUM] Linux kernel (i.MX51) vulnerabilities
Title: Linux kernel (i.MX51) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Stream Control Transmission Protocol (SCTP)
implementation incorrectly calculated lengths. If the net.sctp.addip_enable
variable was turned on, a remote attacker could send specially crafted
traffic to crash the system. (CVE-2011-1573)
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Timo Warns discovered that the EFI GUID partition table was not correctly
parsed. A physically local attacker that could insert mountable devices
could exploit this to crash the system or possibly gain root p
Red Hat
kernel: kernel: net_sched: fix qdisc_notify()
vendor_redhat·2010-05-21·CVSS 7.8
CVE-2011-2525 [HIGH] kernel: kernel: net_sched: fix qdisc_notify()
kernel: kernel: net_sched: fix qdisc_notify()
The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
Statement: This flaw affects Red Hat Enterprise Linux 4 and 5. It did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they have already backported the upstream commit 53b0f080 that addressed this flaw. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1065.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, ht
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify() [fedora-all]
bugzilla·2011-10-25·CVSS 7.8
CVE-2011-2525 [HIGH] CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify() [fedora-all]
CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720552
Please note: this issue affects multiple s
Bugzilla
CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify()
bugzilla·2011-07-12·CVSS 7.8
CVE-2011-2525 [HIGH] CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify()
CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify()
tc_fill_qdisc() should not be called for builtin qdisc, or it dereference a NULL pointer to get device ifindex.
Reference:
http://kerneltrap.org/mailarchive/linux-netdev/2010/5/21/6277805
Upstream commit:
http://git.kernel.org/linus/53b0f08042f04813cd1a7473dacd3edfacb28eb3
Discussion:
Statement:
This flaw affects Red Hat Enterprise Linux 4 and 5. It did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they have already backported the upstream commit 53b0f080 that addressed this flaw. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1065.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/po
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=53b0f08042f04813cd1a7473dacd3edfacb28eb3http://kerneltrap.org/mailarchive/linux-netdev/2010/5/21/6277805http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.35http://openwall.com/lists/oss-security/2011/07/12/1http://rhn.redhat.com/errata/RHSA-2011-1065.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1163.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=720552http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=53b0f08042f04813cd1a7473dacd3edfacb28eb3http://kerneltrap.org/mailarchive/linux-netdev/2010/5/21/6277805http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.35http://openwall.com/lists/oss-security/2011/07/12/1http://rhn.redhat.com/errata/RHSA-2011-1065.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1163.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=720552
2012-02-02
Published