CVE-2011-2184
06.09.2011, 16:55
The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure member, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function, a different vulnerability than CVE-2010-2960.Enginsight
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 𝑥 < 2.6.39.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||||||||||
| linux-ec2 |
| ||||||||||||||||
| linux-flo |
| ||||||||||||||||
| linux-fsl-imx51 |
| ||||||||||||||||
| linux-goldfish |
| ||||||||||||||||
| linux-grouper |
| ||||||||||||||||
| linux-lts-backport-maverick |
| ||||||||||||||||
| linux-lts-backport-natty |
| ||||||||||||||||
| linux-maguro |
| ||||||||||||||||
| linux-mako |
| ||||||||||||||||
| linux-manta |
| ||||||||||||||||
| linux-mvl-dove |
| ||||||||||||||||
| linux-ti-omap4 |
|
Common Weakness Enumeration
References