LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2011-1012 CVE-2011-1082 CVE-2011-1163 CVE-2011-1182 CVE-2011-1476 CVE-2011-1477 CVE-2011-1493
Created:April 18, 2011 Updated:September 14, 2011
Description: From the openSUSE advisory:

CVE-2011-1012: The code for evaluating LDM partitions (in fs/partitions/ldm.c) contained a bug that could crash the kernel for certain corrupted LDM partitions.

CVE-2011-1082: The epoll subsystem in Linux did not prevent users from creating circular epoll file structures, potentially leading to a denial of service (kernel deadlock).

CVE-2011-1163: The code for evaluating OSF partitions (in fs/partitions/osf.c) contained a bug that leaks data from kernel heap memory to userspace for certain corrupted OSF partitions.

CVE-2011-1182: Local attackers could send signals to their programs that looked like coming from the kernel, potentially gaining privileges in the context of setuid programs.

CVE-2011-1476: Specially crafted requests may be written to /dev/sequencer resulting in an underflow when calculating a size for a copy_from_user() operation in the driver for MIDI interfaces. On x86, this just returns an error, but it could have caused memory corruption on other architectures. Other malformed requests could have resulted in the use of uninitialized variables.

CVE-2011-1477: Due to a failure to validate user-supplied indexes in the driver for Yamaha YM3812 and OPL-3 chips, a specially crafted ioctl request could have been sent to /dev/sequencer, resulting in reading and writing beyond the bounds of heap buffers, and potentially allowing privilege escalation.

CVE-2011-1493: In the rose networking stack, when parsing the FAC_NATIONAL_DIGIS facilities field, it was possible for a remote host to provide more digipeaters than expected, resulting in heap corruption. Check against ROSE_MAX_DIGIS to prevent overflows, and abort facilities parsing on failure.

Alerts:
Oracle ELSA-2011-2038 2011-12-27
Oracle ELSA-2011-2038 2011-12-27
Ubuntu USN-1256-1 2011-11-09
Ubuntu USN-1218-1 2011-09-29
Ubuntu USN-1216-1 2011-09-26
Ubuntu USN-1211-1 2011-09-21
Ubuntu USN-1212-1 2011-09-21
Ubuntu USN-1208-1 2011-09-14
Ubuntu USN-1205-1 2011-09-13
Ubuntu USN-1204-1 2011-09-13
Ubuntu USN-1203-1 2011-09-13
Ubuntu USN-1202-1 2011-09-13
Ubuntu USN-1201-1 2011-09-13
Scientific Linux SL-kern-20110823 2011-08-23
Red Hat RHSA-2011:1189-01 2011-08-23
Ubuntu USN-1189-1 2011-08-19
Ubuntu USN-1187-1 2011-08-09
Scientific Linux SL-kern-20110715 2011-07-15
SUSE SUSE-SU-2011:0832-1 2011-07-25
SUSE SUSE-SA:2011:031 2011-07-25
CentOS CESA-2011:0927 2011-07-18
Ubuntu USN-1170-1 2011-07-15
Ubuntu USN-1168-1 2011-07-15
Red Hat RHSA-2011:0927-01 2011-07-15
Ubuntu USN-1167-1 2011-07-13
Ubuntu USN-1161-1 2011-07-13
Ubuntu USN-1159-1 2011-07-13
Ubuntu USN-1162-1 2011-06-29
Ubuntu USN-1164-1 2011-07-06
SUSE SUSE-SU-2011:0737-1 2011-07-05
Ubuntu USN-1183-1 2011-08-03
SUSE SUSE-SU-2011:0711-1 2011-06-29
Ubuntu USN-1160-1 2011-06-28
Red Hat RHSA-2011:0883-01 2011-06-21
Debian DSA-2264-1 2011-06-18
Ubuntu USN-1146-1 2011-06-09
Scientific Linux SL-kern-20110519 2011-05-19
CentOS CESA-2011:0833 2011-05-31
Ubuntu USN-1141-1 2011-05-31
Red Hat RHSA-2011:0833-01 2011-05-31
Debian DSA-2240-1 2011-05-24
SUSE SUSE-SA:2011:017 2011-04-18
openSUSE openSUSE-SU-2011:0346-1 2011-04-18
SUSE SUSE-SA:2011:026 2011-05-20
Red Hat RHSA-2011:0542-01 2011-05-19
Red Hat RHSA-2011:0500-01 2011-05-10
openSUSE openSUSE-SU-2011:0416-1 2011-04-29
SUSE SUSE-SA:2011:019 2011-04-28
openSUSE openSUSE-SU-2011:0399-1 2011-04-28
Ubuntu USN-1390-1 2012-03-06
Ubuntu USN-1394-1 2012-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds