Input validation error in Linux kernel - CVE-2011-3188

 

Input validation error in Linux kernel - CVE-2011-3188

Published: May 25, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44030
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3188
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.


Affected software

Linux kernel
Amazon Linux AMI
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000

How to mitigate CVE-2011-3188

Install update from vendor's website.

Linux kernel - update to 3.1
IBM Storwize V3500 - update to 7.1.0.0
IBM Storwize V3700 - update to 7.1.0.0
IBM Storwize V5000 - update to 7.1.0.0
IBM Storwize V7000 - update to 7.1.0.0

External References

Related Security Bulletins