cbcvebase.
CVE-2011-4914
published 2012-06-21

CVE-2011-4914: The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent…

medium6.4CVSS 3.1
AVNACLAuNCPINAP
The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

Affected

10 ranges
VendorProductVersion rangeFixed in
linuxlinux_kernel<= 2.6.38.8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
novellsuse_linux_enterprise_server