CVE-2011-1171

N/A Unknown
Published: June 22, 2011 Modified: April 29, 2026
View on NVD

Description

net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://downloads.avaya.com/css/P8/documents/100145416
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=linux-kernel&m=129978077609894&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://rhn.redhat.com/errata/RHSA-2011-0833.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/8278
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/8283
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2011/03/18/15
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.openwall.com/lists/oss-security/2011/03/21/1
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.openwall.com/lists/oss-security/2011/03/21/4
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.redhat.com/show_bug.cgi?id=689327
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.4%
33th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

linux