Release date:
Updated on:
Affected Systems:
Linux kernel
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47852
Cve id: CVE-2011-1767
Linux Kernel is the Kernel used by open source Linux.
The Linux Kernel "ip gre" module has a denial of service vulnerability of NULL pointer reference. A local attacker can exploit this vulnerability to cause a Kernel crash. This vulnerability can also cause DoS attacks to legitimate users and arbitrary code execution.
The GRE receive hook routine can be called after the Protocol is added. If netns stuff has not been initialized, the system will crash in net_generic. If ip_gre is compiled into a module and the package is received when the module is loaded, Remote crash occurs.
<* Source: Alexey Dobriyan
Link: http://patchwork.ozlabs.org/patch/45553/
Http://xorl.wordpress.com/2011/05/14/cve-2011-1767-linux-kernel-ip-gre-remote-race-condition/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/