CVE-2011-4913

Linux Kernel < 2.6.39 - Denial of Service and Stack-Based Buffer Overflow via ROSE Socket

Title source: llm
STIX 2.1

Description

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

Scores

EPSS 0.0095
EPSS Percentile 76.6%

Details

CWE
CWE-20
Status published
Products (10)
linux/linux_kernel 2.6.38 (9 CPE variants)
linux/linux_kernel 2.6.38.1
linux/linux_kernel 2.6.38.2
linux/linux_kernel 2.6.38.3
linux/linux_kernel 2.6.38.4
linux/linux_kernel 2.6.38.5
linux/linux_kernel 2.6.38.6
linux/linux_kernel 2.6.38.7
linux/linux_kernel < 2.6.38.8
novell/suse_linux_enterprise_server 10.0 sp4
Published Jun 21, 2012
Tracked Since Feb 18, 2026