Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4132

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2011-4132
Last Modified 03 Sep 2015 10:23:14
Published 27 Jan 2012 10:55:04
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2011-4132

Summary

The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."

Vulnerable Systems

Operating System

  • Linux Kernel 2.6

  • Suse Linux Enterprise Server 10


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=753341

MISC - http://xorl.wordpress.com/2011/12/08/cve-2011-4132-linux-kernel-jbdjbd2-local-dos/

BID - 50663

MLIST - [oss-security] 20111113 Re: CVE Request -- kernel: jbd/jbd2: invalid value of first log block leads to oops

MLIST - [oss-security] 20111111 CVE Request -- kernel: jbd/jbd2: invalid value of first log block leads to oops

SECTRACK - 1026325

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=8762202dd0d6e46854f786bdb6fb3780a1625efe

SECUNIA - 48898

SUSE - SUSE-SU-2015:0812

Related Patches

Red Hat 2012:0007-01 RHSA Important: kernel security, bug fix, and enhancement update for RHEL 5 x86

Red Hat 2012:0007-01 RHSA Important: kernel security, bug fix, and enhancement update for RHEL 5 x86_64

Novell SUSE 2012:5723 kernel security update for SLE 11 SP1 i586

Novell SUSE 2012:5732 kernel security update for SLE 11 SP1 x86_64

Novell SUSE 2012:6164 kernel security update for SLE 11 SP2 x86_64

Novell SUSE 2012:6172 kernel security update for SLE 11 SP2 i586


Last Updated: 27 May 2016 10:57:24