CVE-2011-3347
published 2013-06-08CVE-2011-3347: A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is…
PriorityP415medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
0.82%
53.6th percentile
A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| linux | linux_kernel | >= 0 < 4.2.0-16.19 | 4.2.0-16.19 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-03-29
CVE-2011-3347 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: Several security issues were fixed in the kernel.
Somnath Kotur discovered an error in the Linux kernel's VLAN (virtual lan)
and be2net drivers. An attacker on the local network could exploit this
flaw to cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. l
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-03-27·CVSS 4.6
CVE-2011-3347 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to deny services if it received specially crafted
local area network traffic.
Somnath Kotur discovered an error in the Linux kernel's VLAN (virtual lan)
and be2net drivers. An attacker on the local network could exploit this
flaw to cause a denial of service. (CVE-2011-3347)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corrupt filesystem. A user-assisted remote attacker could exploit this flaw
to cause a denial of service. (CVE-2012-2100)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-03-27·CVSS 4.6
CVE-2011-3347 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Somnath Kotur discovered an error in the Linux kernel's VLAN (virtual lan)
and be2net drivers. An attacker on the local network could exploit this
flaw to cause a denial of service. (CVE-2011-3347)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
kernel: be2net: promiscuous mode and non-member VLAN packets DoS
vendor_redhat·2011-10-20·CVSS 4.6
CVE-2011-3347 [MEDIUM] kernel: be2net: promiscuous mode and non-member VLAN packets DoS
kernel: be2net: promiscuous mode and non-member VLAN packets DoS
A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
Statement: This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for ServerEngines' 10Gbps network adapter - BladeEngine. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2011-1530.html. A future kernel update in Red Hat Enterprise MRG may
GHSA
GHSA-hf88-fvh2-2xgw: A certain Red Hat patch to the be2net implementation in the kernel package before 2
ghsa_unreviewed·2022-05-14
CVE-2011-3347 [MEDIUM] GHSA-hf88-fvh2-2xgw: A certain Red Hat patch to the be2net implementation in the kernel package before 2
A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
OSV
CVE-2011-3347: A certain Red Hat patch to the be2net implementation in the kernel package before 2
osv·2011-10-21·CVSS 4.6
CVE-2011-3347 [MEDIUM] CVE-2011-3347: A certain Red Hat patch to the be2net implementation in the kernel package before 2
A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS [fedora-all]
bugzilla·2011-10-25·CVSS 4.6
CVE-2011-3347 [MEDIUM] CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS [fedora-all]
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=736425
Please note: this issue
Bugzilla
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
bugzilla·2011-09-07·CVSS 4.6
CVE-2011-3347 [MEDIUM] CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
When interface is put in promiscuous mode and it receives VLAN packets, but no VLANS are configured on that interface , then the kernel crashes in the 8021q module.
Acknowledgements:
Red Hat would like to thank Somnath Kotur for reporting this issue.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:1386 https://rhn.redhat.com/errata/RHSA-2011-1386.html
---
Statement:
This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for ServerEngines' 10Gbps network adapter - Bla
2013-06-08
Published