CVE-2011-1493

Linux Kernel < 2.6.39 - Denial of Service via ROSE FAC_NATIONAL_DIGIS Data

Title source: llm
STIX 2.1

Description

Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DIGIS data that specifies a large number of digipeaters, and then sending this data to a ROSE socket.

Scores

EPSS 0.0336
EPSS Percentile 87.6%

Details

Status published
Products (9)
linux/linux_kernel 2.6.38 (9 CPE variants)
linux/linux_kernel 2.6.38.1
linux/linux_kernel 2.6.38.2
linux/linux_kernel 2.6.38.3
linux/linux_kernel 2.6.38.4
linux/linux_kernel 2.6.38.5
linux/linux_kernel 2.6.38.6
linux/linux_kernel 2.6.38.7
linux/linux_kernel < 2.6.38.8
Published Jun 21, 2012
Tracked Since Feb 18, 2026