CVE-2011-2942
published 2013-06-08CVE-2011-2942: A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.79%
76.1th percentile
A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging connectivity to a network interface that uses an Ethernet bridge device.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cgjv-rvfj-3vrq: A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward
ghsa_unreviewed·2022-05-17
CVE-2011-2942 [MEDIUM] GHSA-cgjv-rvfj-3vrq: A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward
A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging connectivity to a network interface that uses an Ethernet bridge device.
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2011-12-08·CVSS 2.1
CVE-2011-2942 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Peter Huewe discovered an information leak in the handling of reading
security-related TPM data. A local, unprivileged user could read the
results of a previous TPM command. (CVE-2011-1162)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Qianfeng Zhang discovered that the bridge networking interface incorrectly
handled certain network packets. A remote attacker could exploit this to
crash the system, leading to a denial of service. (CVE-2011-2942)
Yasuaki Ishimatsu discovered a flaw in the kernel's clock implementation. A
local unpri
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-11-09·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear
memory. A local attacker could exploit this to read kernel stack memory,
leading to a loss of privacy. (CVE-2011-1078)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check
that device name strings were NULL terminated. A local attacker could
exploit this to crash the system,
Red Hat
kernel: bridge: null pointer dereference in __br_deliver
vendor_redhat·2011-10-20·CVSS 6.8
CVE-2011-2942 [MEDIUM] CWE-476 kernel: bridge: null pointer dereference in __br_deliver
kernel: bridge: null pointer dereference in __br_deliver
A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging connectivity to a network interface that uses an Ethernet bridge device.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Affected
Package: realt
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver [fedora-all]
bugzilla·2011-10-25·CVSS 6.8
CVE-2011-2942 [MEDIUM] CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver [fedora-all]
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=730917
Please note: this issue affects
Bugzilla
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
bugzilla·2011-08-16·CVSS 6.8
CVE-2011-2942 [MEDIUM] CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
In the br_forward_finish() function, we may call kfree() on the skb we are forwarding, and so, after it, we should not dereference skb->dev pointer. With the fix, we save skb->dev before calling the br_forward_finish() function, so that we can use it afterwards.
Discussion:
Statement:
This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:1386 https://rhn.redhat.com/errata/RHSA-2011-1386.html
---
Created kernel tracking bugs for this issue
Affe
2013-06-08
Published