CVE-2011-2182
The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cae13fe4cc3f24820ffb990c09110626837e85d4
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://www.openwall.com/lists/oss-security/2011/06/05/1Patch
- http://www.securityfocus.com/bid/52334
- https://github.com/torvalds/linux/commit/cae13fe4cc3f24820ffb990c09110626837e85d4Patch
- http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cae13fe4cc3f24820ffb990c09110626837e85d4
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://www.openwall.com/lists/oss-security/2011/06/05/1Patch
- http://www.securityfocus.com/bid/52334
- https://github.com/torvalds/linux/commit/cae13fe4cc3f24820ffb990c09110626837e85d4Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.