Release date:
Updated on:
Affected Systems:
Linux kernel <= 3.3
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2011-4604
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.3, the function bat_socket_read in net/batman-adv/icmp_socket.c has a security vulnerability, which allows remote attackers to use specially crafted batman-adv ICMP packets, this vulnerability can cause DoS or other attacks.
<* Source: Kees Cook (kees@ubuntu.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 767495
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Http://www.openwall.com/lists/oss-security/2011/12/12/1
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = b5a1eeef04cc7859f34dec9b72ea1b28e4aba07c
Http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.3.bz2
Https://github.com/torvalds/linux/commit/b5a1eeef04cc7859f34dec9b72ea1b28e4aba07c