CVE-2011-2189
10.10.2011, 10:55
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 ≤ 2.6.32 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_mrg | 2.0 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 10.10 |
canonical | ubuntu_linux | 11.04 |
canonical | ubuntu_linux | 11.10 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References