CVE-2011-2184
Linux Kernel < 2.6.39.1 - Denial of Service via KEYCTL_SESSION_TO_PARENT Keyctl Argument
Title source: llmDescription
The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure member, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function, a different vulnerability than CVE-2010-2960.
References (9)
Core 9
Core References
Broken Link x_refsource_misc
http://alt.swiecki.net/linux_kernel/sys_open-kmem_cache_alloc-2.6.39-rc4.txt
Patch x_refsource_confirm
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f7285b5d631fd6096b11c6af0058ed3a2b30ef4e
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/03/2
Third Party Advisory mailing-list
x_refsource_mlist
https://lkml.org/lkml/2011/5/24/502
Third Party Advisory mailing-list
x_refsource_mlist
https://lkml.org/lkml/2011/5/23/199
Patch, Third Party Advisory mailing-list
x_refsource_mlist
https://lkml.org/lkml/2011/5/25/265
Patch, Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/8371
Broken Link x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.1
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/06/2
Scores
EPSS
0.0038
EPSS Percentile
30.2%
Details
CWE
CWE-476
Status
published
Products (1)
linux/linux_kernel
< 2.6.39.1
Published
Sep 06, 2011
Tracked Since
Feb 18, 2026