VulnerabilityModified
CVE-2011-2491
The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.
MEDIUM 4.9EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- linux/linux kernel · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://ftp.osuosl.org/pub/linux/kernel/v3.0/ChangeLog-3.0Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0b760113a3a155269a3fba93a409c640031dd68f
- http://rhn.redhat.com/errata/RHSA-2011-1212.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2011/06/23/6Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=709393Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/0b760113a3a155269a3fba93a409c640031dd68fPatch, Third Party Advisory
- http://ftp.osuosl.org/pub/linux/kernel/v3.0/ChangeLog-3.0Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0b760113a3a155269a3fba93a409c640031dd68f
- http://rhn.redhat.com/errata/RHSA-2011-1212.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2011/06/23/6Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=709393Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/0b760113a3a155269a3fba93a409c640031dd68fPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.