Permissions, Privileges, and Access Controls in libcgroup - CVE-2011-1022

 

Permissions, Privileges, and Access Controls in libcgroup - CVE-2011-1022

Published: March 22, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45180
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2011-1022
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: MATSUMOTO Ryosuke
Affected software:
libcgroup

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.


How to mitigate CVE-2011-1022

Install update from vendor's website.

Sources