CVE-2011-4621

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.

References

http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f26f9aff6aaf67e9a430d16c266f91b13a5bff64

http://www.openwall.com/lists/oss-security/2011/12/21/6

https://bugzilla.redhat.com/show_bug.cgi?id=769711

https://github.com/torvalds/linux/commit/f26f9aff6aaf67e9a430d16c266f91b13a5bff64

Details

Source: MITRE

Published: 2012-05-17

Updated: 2020-07-27

Type: CWE-835

Risk Information

CVSS v2

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
68411Oracle Linux 6 : kernel (ELSA-2011-1849)NessusOracle Linux Local Security Checks
medium
58289USN-1394-1 : Linux kernel (OMAP4) vulnerabilitiesNessusUbuntu Local Security Checks
high
57404CentOS 6 : kernel (CESA-2011:1849)NessusCentOS Local Security Checks
medium
57391RHEL 6 : kernel (RHSA-2011:1849)NessusRed Hat Local Security Checks
medium
52500Ubuntu 10.10 : linux vulnerabilities (USN-1081-1)NessusUbuntu Local Security Checks
high
801399CentOS RHSA-2011-1849 Security CheckLog Correlation EngineGeneric
high