CVE-2011-1163
Summary
| CVE | CVE-2011-1163 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-10 02:51:19 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 5.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 5.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 10 | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [security-announce] SUSE-SU-2015:0812-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| SecurityTracker: Linux Kernel OSF Partition Table Buffer Overflow Lets Local Users Obtain Information | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| oss-security - CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Patch, Third Party Advisory |
| + fs-partitions-osfc-corrupted-osf-partition-table-can-cause-information-disclosure.patch added to -mm tree -- MM Commits | af854a3a-2127-422b-91ae-364da2661108 | www.spinics.net | Mailing List, Patch, Third Party Advisory |
| ASA-2011-208 (RHSA-2011-0833) | af854a3a-2127-422b-91ae-364da2661108 | downloads.avaya.com | Third Party Advisory |
| Linux Kernel 'fs/partitions/osf.c' Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 688021 – (CVE-2011-1163) CVE-2011-1163 kernel: fs/partitions: Corrupted OSF partition table infoleak | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| www.pre-cert.de/advisories/PRE-SA-2011-02.txt | af854a3a-2127-422b-91ae-364da2661108 | www.pre-cert.de | Third Party Advisory |
| Linux Kernel 2.4 and 2.6 disclosure of sensitive information - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| oss-security - Re: CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Patch, Third Party Advisory |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Broken Link |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.