CVE-2011-0714

Linux Kernel 2.6.32 on Red Hat Enterprise Linux 6 - Use-After-Free in RPC Server Sockets

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/08/17
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=678144
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/09/1
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2011-0329.html

Scores

EPSS 0.0095
EPSS Percentile 57.9%

Details

CWE
CWE-399
Status published
Products (2)
linux/linux_kernel 2.6.32
redhat/enterprise_linux 6.0
Published May 04, 2011
Tracked Since Feb 18, 2026