CVE-2011-4112

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2012
Last modified:
11/04/2025

Description

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.1 (excluding)
cpe:2.3:o:avaya:9608_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9608:-:*:*:*:*:*:*:*
cpe:2.3:o:avaya:9608g_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9608g:-:*:*:*:*:*:*:*
cpe:2.3:o:avaya:9611g_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9611g:-:*:*:*:*:*:*:*
cpe:2.3:o:avaya:9621g_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9621g:-:*:*:*:*:*:*:*
cpe:2.3:o:avaya:9641g_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9641g:-:*:*:*:*:*:*:*
cpe:2.3:o:avaya:9641gs_firmware:*:*:*:*:*:*:*:* 6.0 (including) 6.6.0 (including)
cpe:2.3:h:avaya:9641gs:-:*:*:*:*:*:*:*