CVE-2011-4914

Linux Kernel < 2.6.39 - Denial of Service via ROSE Protocol Data-Length Mismatch

Title source: llm
STIX 2.1

Description

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

Scores

EPSS 0.0127
EPSS Percentile 79.7%

Details

CWE
CWE-20
Status published
Products (10)
linux/linux_kernel 2.6.38 (9 CPE variants)
linux/linux_kernel 2.6.38.1
linux/linux_kernel 2.6.38.2
linux/linux_kernel 2.6.38.3
linux/linux_kernel 2.6.38.4
linux/linux_kernel 2.6.38.5
linux/linux_kernel 2.6.38.6
linux/linux_kernel 2.6.38.7
linux/linux_kernel < 2.6.38.8
novell/suse_linux_enterprise_server 10.0 sp4
Published Jun 21, 2012
Tracked Since Feb 18, 2026