CVE-2011-2494

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 3.0.34
linuxlinux_kernel
3.0.1
linuxlinux_kernel
3.0.2
linuxlinux_kernel
3.0.3
linuxlinux_kernel
3.0.4
linuxlinux_kernel
3.0.5
linuxlinux_kernel
3.0.6
linuxlinux_kernel
3.0.7
linuxlinux_kernel
3.0.8
linuxlinux_kernel
3.0.9
linuxlinux_kernel
3.0.10
linuxlinux_kernel
3.0.11
linuxlinux_kernel
3.0.12
linuxlinux_kernel
3.0.13
linuxlinux_kernel
3.0.14
linuxlinux_kernel
3.0.15
linuxlinux_kernel
3.0.16
linuxlinux_kernel
3.0.17
linuxlinux_kernel
3.0.18
linuxlinux_kernel
3.0.19
linuxlinux_kernel
3.0.20
linuxlinux_kernel
3.0.21
linuxlinux_kernel
3.0.22
linuxlinux_kernel
3.0.23
linuxlinux_kernel
3.0.24
linuxlinux_kernel
3.0.25
linuxlinux_kernel
3.0.26
linuxlinux_kernel
3.0.27
linuxlinux_kernel
3.0.28
linuxlinux_kernel
3.0.29
linuxlinux_kernel
3.0.30
linuxlinux_kernel
3.0.31
linuxlinux_kernel
3.0.32
linuxlinux_kernel
3.0.33
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
not-affected
quantal
not-affected
precise
not-affected
oneiric
Fixed 3.0.0-13.21
released
natty
Fixed 2.6.38-13.52
released
maverick
Fixed 2.6.35-30.61
released
lucid
Fixed 2.6.32-35.78
released
hardy
Fixed 2.6.24-29.95
released
linux-aws
zesty
dne
yakkety
dne
xenial
not-affected
trusty
not-affected
precise
dne
linux-ec2
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
ignored
lucid
Fixed 2.6.32-319.39
released
hardy
dne
linux-flo
zesty
dne
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
dne
quantal
dne
precise
dne
lucid
dne
linux-fsl-imx51
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
Fixed 2.6.31-611.29
released
hardy
dne
linux-gke
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-goldfish
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-grouper
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
not-affected
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-hwe
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-hwe-edge
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-lts-backport-maverick
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
Fixed 2.6.35-30.61~lucid1
released
hardy
dne
linux-lts-backport-natty
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
Fixed 2.6.38-13.52~lucid1
released
hardy
dne
linux-lts-backport-oneiric
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
Fixed 3.0.0-13.21~lucid1
released
hardy
dne
linux-lts-trusty
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
precise
not-affected
lucid
dne
linux-lts-utopic
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
dne
lucid
dne
linux-lts-vivid
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
dne
lucid
dne
linux-lts-wily
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
trusty
dne
precise
dne
linux-lts-xenial
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
trusty
not-affected
precise
dne
linux-maguro
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-mako
zesty
dne
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-manta
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-mvl-dove
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
Fixed 2.6.32-419.37
released
lucid
Fixed 2.6.32-219.37
released
hardy
dne
linux-raspi2
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
dne
trusty
dne
precise
dne
linux-snapdragon
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
dne
trusty
dne
precise
dne
linux-ti-omap4
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
not-affected
quantal
not-affected
precise
not-affected
oneiric
Fixed 3.0.0-1206.11
released
natty
Fixed 2.6.38-1209.17
released
maverick
Fixed 2.6.35-903.26
released
lucid
dne
hardy
dne