CVE-2011-1082
Last modified
CVE-2011-1082 is a vulnerability of currently unknown severity. fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.38 |
References
- http://openwall.com/lists/oss-security/2011/03/02/1Mailing List, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/02/2Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=681575Issue Tracking, Patch, Third Party Advisory
- https://lkml.org/lkml/2011/2/5/220Mailing List, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/02/1Mailing List, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/02/2Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=681575Issue Tracking, Patch, Third Party Advisory
- https://lkml.org/lkml/2011/2/5/220Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1082?
How severe is CVE-2011-1082?
How do I fix CVE-2011-1082?
Are you affected by CVE-2011-1082?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
