Input validation error in Linux kernel - CVE-2011-1163

 

Input validation error in Linux kernel - CVE-2011-1163

Published: April 10, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45141
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1163
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.


Affected software

Linux kernel

How to mitigate CVE-2011-1163

Install update from vendor's website.

Linux kernel - update to 2.6.38

External References

Related Security Bulletins