CVE Vulnerabilities

CVE-2011-1022

Published: Mar 22, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.

Affected Software

NameVendorStart VersionEnd Version
LibcgroupBalbir_singh*0.37 (including)
LibcgroupBalbir_singh0.1b (including)0.1b (including)
LibcgroupBalbir_singh0.1c (including)0.1c (including)
LibcgroupBalbir_singh0.2 (including)0.2 (including)
LibcgroupBalbir_singh0.3 (including)0.3 (including)
LibcgroupBalbir_singh0.31 (including)0.31 (including)
LibcgroupBalbir_singh0.32 (including)0.32 (including)
LibcgroupBalbir_singh0.32.1 (including)0.32.1 (including)
LibcgroupBalbir_singh0.32.2 (including)0.32.2 (including)
LibcgroupBalbir_singh0.33 (including)0.33 (including)
LibcgroupBalbir_singh0.34 (including)0.34 (including)
LibcgroupBalbir_singh0.35 (including)0.35 (including)
LibcgroupBalbir_singh0.35.1 (including)0.35.1 (including)
LibcgroupBalbir_singh0.36 (including)0.36 (including)
LibcgroupBalbir_singh0.36.1 (including)0.36.1 (including)
LibcgroupBalbir_singh0.36.2 (including)0.36.2 (including)
LibcgroupBalbir_singh0.37-rc1 (including)0.37-rc1 (including)
Red Hat Enterprise Linux 6RedHatlibcgroup-0:0.36.1-6.el6_0.1*
LibcgroupUbuntuartful*
LibcgroupUbuntukarmic*
LibcgroupUbuntulucid*
LibcgroupUbuntumaverick*
LibcgroupUbuntunatty*
LibcgroupUbuntuoneiric*
LibcgroupUbuntuprecise*
LibcgroupUbuntuquantal*
LibcgroupUbunturaring*
LibcgroupUbuntusaucy*
LibcgroupUbuntuupstream*
LibcgroupUbuntuutopic*
LibcgroupUbuntuvivid*
LibcgroupUbuntuwily*
LibcgroupUbuntuyakkety*
LibcgroupUbuntuzesty*

References