CVE-2011-2689
published 2011-07-28CVE-2011-2689: The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.41%
33.4th percentile
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 3.0 | 3.0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-11-09·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear
memory. A local attacker could exploit this to read kernel stack memory,
leading to a loss of privacy. (CVE-2011-1078)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check
that device name strings were NULL terminated. A local attacker could
exploit this to crash the system,
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-09-21·CVSS 2.1
CVE-2011-0463 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Goldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly
clear memory when writing certain file holes. A local attacker could
exploit this to read uninitialized data from the disk, leading to a loss of
privacy. (CVE-2011-0463)
Timo Warns discovered that the LDM disk partition handling code did not
correctly handle certain values. By inserting a specially crafted disk
device, a local attacker could exploit this to gain root privileges.
(CVE-2011-1017)
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially incr
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-09-21·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws have been fixed.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Dan Rosenberg discovered that the X.25 Rose network stack did not correctly
handle certain fields. If a system was running with Rose enabled, a remote
attacker could send specially crafted traffic to gain root privileges.
(CVE-2011-1493)
Vasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not
correctly check the origin of mount points. A local attacker could exploit
this to trick the syst
Red Hat
kernel: gfs2: make sure fallocate bytes is a multiple of blksize
vendor_redhat·2011-04-26·CVSS 4.9
CVE-2011-2689 [MEDIUM] kernel: gfs2: make sure fallocate bytes is a multiple of blksize
kernel: gfs2: make sure fallocate bytes is a multiple of blksize
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and Red Hat Enterprise MRG as they did not provide support for the Global File System 2 (GFS2). This has been addressed in Red Hat Enterprise Linux 5 and 6 via https://rhn.redhat.com/errata/RHSA-2011-1065.html and https://rhn.redhat.com/errata/RHSA-2011-1189.html.
Package: kernel (Red Hat Enterprise Linux 4) -
GHSA
GHSA-gfx4-r3v9-vph4: The gfs2_fallocate function in fs/gfs2/file
ghsa_unreviewed·2022-05-13
CVE-2011-2689 [MEDIUM] CWE-400 GHSA-gfx4-r3v9-vph4: The gfs2_fallocate function in fs/gfs2/file
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
OSV
CVE-2011-2689: The gfs2_fallocate function in fs/gfs2/file
osv·2011-07-28·CVSS 4.9
CVE-2011-2689 [MEDIUM] CVE-2011-2689: The gfs2_fallocate function in fs/gfs2/file
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize [fedora-all]
bugzilla·2011-10-25·CVSS 4.9
CVE-2011-2689 [MEDIUM] CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize [fedora-all]
CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720861
Please note: this issue
Bugzilla
CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize
bugzilla·2011-07-13·CVSS 4.9
CVE-2011-2689 [MEDIUM] CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize
CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize
The GFS2 fallocate code chooses a target size to for allocating chunks of space. Whenever it can't find any resource groups with enough space free, it halves its target. Since this target is in bytes, eventually it will no longer be a multiple of blksize. As long as there is more space available in the resource group than the target, this isn't a problem, since gfs2 will use the actual space available, which is always a multiple of blksize. However, when gfs couldn't fallocate a bigger chunk than the target, it was using the non-blksize aligned number. This caused a BUG in later code that required blksize aligned offsets.
Upstream commit:
http://git.kernel.org/linus/6905d9e4dda6112f007e9090bca80507da158e63
D
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6905d9e4dda6112f007e9090bca80507da158e63http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2011-1065.htmlhttp://secunia.com/advisories/45193http://securitytracker.com/id?1025776http://www.kernel.org/pub/linux/kernel/v3.0/testing/ChangeLog-3.0-rc1http://www.openwall.com/lists/oss-security/2011/07/13/1http://www.securityfocus.com/bid/48677https://bugzilla.redhat.com/show_bug.cgi?id=720861https://exchange.xforce.ibmcloud.com/vulnerabilities/68557http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6905d9e4dda6112f007e9090bca80507da158e63http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2011-1065.htmlhttp://secunia.com/advisories/45193http://securitytracker.com/id?1025776http://www.kernel.org/pub/linux/kernel/v3.0/testing/ChangeLog-3.0-rc1http://www.openwall.com/lists/oss-security/2011/07/13/1http://www.securityfocus.com/bid/48677https://bugzilla.redhat.com/show_bug.cgi?id=720861https://exchange.xforce.ibmcloud.com/vulnerabilities/68557
2011-07-28
Published