ID:4478 - Exploit for Resource exhaustion in Linux kernel - CVE-2011-2918

 
Main Vulnerability Database Exploits ID:4478 - Exploit for Resource exhaustion in Linux kernel - CVE-2011-2918

ID:4478 - Exploit for Resource exhaustion in Linux kernel - CVE-2011-2918

Published: August 11, 2020


Vulnerability identifier: #VU44029
Vulnerability risk: Low
CVE-ID: CVE-2011-2918
CWE-ID: CWE-400
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.


Remediation

Install update from vendor's website.