CVE Vulnerabilities

CVE-2011-1022

Published: Mar 22, 2011 | Modified: Sep 07, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.

Affected Software

Name Vendor Start Version End Version
Libcgroup Balbir_singh * 0.37 (including)
Libcgroup Balbir_singh 0.1b (including) 0.1b (including)
Libcgroup Balbir_singh 0.1c (including) 0.1c (including)
Libcgroup Balbir_singh 0.2 (including) 0.2 (including)
Libcgroup Balbir_singh 0.3 (including) 0.3 (including)
Libcgroup Balbir_singh 0.31 (including) 0.31 (including)
Libcgroup Balbir_singh 0.32 (including) 0.32 (including)
Libcgroup Balbir_singh 0.32.1 (including) 0.32.1 (including)
Libcgroup Balbir_singh 0.32.2 (including) 0.32.2 (including)
Libcgroup Balbir_singh 0.33 (including) 0.33 (including)
Libcgroup Balbir_singh 0.34 (including) 0.34 (including)
Libcgroup Balbir_singh 0.35 (including) 0.35 (including)
Libcgroup Balbir_singh 0.35.1 (including) 0.35.1 (including)
Libcgroup Balbir_singh 0.36 (including) 0.36 (including)
Libcgroup Balbir_singh 0.36.1 (including) 0.36.1 (including)
Libcgroup Balbir_singh 0.36.2 (including) 0.36.2 (including)
Libcgroup Balbir_singh 0.37-rc1 (including) 0.37-rc1 (including)

References