UBUNTU-CVE-2011-2525
Dashboard / Vulnerabilities / UBUNTU-CVE-2011-2525
UBUNTU-CVE-2011-2525
Summary:
Details: The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
References: https://ubuntu.com/security/CVE-2011-2525, http://kerneltrap.org/mailarchive/linux-netdev/2010/5/21/6277805, http://www.debian.org/security/2011/dsa-2303, https://ubuntu.com/security/notices/USN-1241-1, https://ubuntu.com/security/notices/USN-1256-1, https://ubuntu.com/security/notices/USN-1268-1, https://ubuntu.com/security/notices/USN-1269-1, https://ubuntu.com/security/notices/USN-1274-1, https://ubuntu.com/security/notices/USN-1286-1, https://www.cve.org/CVERecord?id=CVE-2011-2525
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
