CVE-2011-1019

Linux kernel <2.6.38 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

References (5)

Core 5
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://github.com/torvalds/linux/commit/8909c9ad8ff03611c9c96c9a92656213e4bb495b
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=680360
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/02/25/1

Scores

EPSS 0.0044
EPSS Percentile 36.5%

Details

Status published
Products (1)
linux/linux_kernel < 2.6.38
Published Mar 01, 2013
Tracked Since Feb 18, 2026