CVE-2011-1022
Summary
| CVE | CVE-2011-1022 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-22 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Balbir Singh | Libcgroup | 0.1b | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.1c | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.2 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.3 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.31 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.32 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.32.1 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.32.2 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.33 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.34 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.35 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.35.1 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.36 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.36.1 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.36.2 | All | All | All |
| Application | Balbir Singh | Libcgroup | 0.37 | rc1 | All | All |
| Application | Balbir Singh | Libcgroup | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 14 Update: libcgroup-0.36.2-6.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - Re: CVE request: libcgroup: Failure to verify netlink messages | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| Control Group Configuration / [Libcg-devel] Fwd: libcgroup netlink | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| SUSE update for libcgroup - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| libcgroup Lets Local Users Spoof NETLINK Messages - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Debian -- Security Information -- DSA-2193-1 libcgroup | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - CVE request: libcgroup: Failure to verify netlink messages | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| openSUSE-SU-2011:0316-1 (important): libcgroup1: Fixed heap-based buffer | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat update for libcgroup - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Download Control Group Configuration from SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| [SECURITY] Fedora 15 Update: libcgroup-0.37.1-1.fc15 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Control Group Configuration / [Libcg-devel] [PATCH 2/2] cgrulesengd: Ignore netlink messages that don't come from the kernel. | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| #615987 - CVE-2011-1022 - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Patch |
| 680409 – (CVE-2011-1022) CVE-2011-1022 libcgroup: Uncheck origin of NETLINK messages | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| oss-security - Re: CVE request: libcgroup: Failure to verify netlink messages | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| Security Advisory SA43758 - Debian update for libcgroup - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - Re: CVE request: libcgroup: Failure to verify netlink messages | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: CVE request: libcgroup: Failure to verify netlink messages | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Fedora update for libcgroup - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.