LWN.net Logo

kernel: denial of service

Package(s):kernel CVE #(s):CVE-2011-1780 CVE-2011-2525 CVE-2011-2689
Created:July 21, 2011 Updated:November 21, 2011
Description: From the Red Hat advisory:

* A flaw was found in the way the Xen hypervisor implementation handled instruction emulation during virtual machine exits. A malicious user-space process running in an SMP guest could trick the emulator into reading a different instruction than the one that caused the virtual machine to exit. An unprivileged guest user could trigger this flaw to crash the host. This only affects systems with both an AMD x86 processor and the AMD Virtualization (AMD-V) extensions enabled. (CVE-2011-1780, Important)

* A flaw allowed the tc_fill_qdisc() function in the Linux kernel's packet scheduler API implementation to be called on built-in qdisc structures. A local, unprivileged user could use this flaw to trigger a NULL pointer dereference, resulting in a denial of service. (CVE-2011-2525, Moderate)

* A flaw was found in the way space was allocated in the Linux kernel's Global File System 2 (GFS2) implementation. If the file system was almost full, and a local, unprivileged user made an fallocate() request, it could result in a denial of service. Note: Setting quotas to prevent users from using all available disk space would prevent exploitation of this flaw. (CVE-2011-2689, Moderate)

Alerts:
Oracle ELSA-2011-2037 2011-12-15
Ubuntu USN-1286-1 2011-12-03
Ubuntu USN-1269-1 2011-11-21
Ubuntu USN-1274-1 2011-11-21
Ubuntu USN-1256-1 2011-11-09
Ubuntu USN-1268-1 2011-11-21
Ubuntu USN-1241-1 2011-10-25
Debian DSA-2310-1 2011-09-22
CentOS CESA-2011:1065 2011-09-22
Ubuntu USN-1211-1 2011-09-21
Ubuntu USN-1212-1 2011-09-21
Debian DSA-2303-2 2011-09-10
Debian DSA-2303-1 2011-09-08
Scientific Linux SL-kern-20110823 2011-08-23
Red Hat RHSA-2011:1189-01 2011-08-23
Red Hat RHSA-2011:1163-01 2011-08-16
Red Hat RHSA-2011:1065-01 2011-07-21
openSUSE openSUSE-SU-2012:0206-1 2012-02-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds