Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
BID:49152
Info
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
| Bugtraq ID: | 49152 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2918 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 15 2011 12:00AM |
| Updated: | Apr 13 2015 10:13PM |
| Credit: | Vince Weaver |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server Unsupported Extras 11 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Real Time 11 SP1 SuSE SUSE Linux Enterprise High Availability Extension 11 SP1 SuSE Suse Linux Enterprise Desktop 11 SP1 Redhat MRG Realtime for RHEL 6 Server 2 Redhat Linux 6.2 E sparc Redhat Linux 6.2 E i386 Redhat Linux 6.2 E alpha Redhat Linux 6.2 sparc Redhat Linux 6.2 i386 Redhat Linux 6.2 alpha Redhat Linux 6.1 sparc Redhat Linux 6.1 i386 Redhat Linux 6.1 alpha Redhat Linux 6.1 Redhat Linux 6.0 x Redhat Linux 6.0 sparc Redhat Linux 6.0 alpha Redhat Linux 6.0 Redhat Linux 6.2 Redhat Enterprise MRG v1 for Red Hat Enterprise Linux ES version 4 Redhat Enterprise MRG v1 for Red Hat Enterprise Linux AS verison 4 Redhat Enterprise MRG v1 for Red Hat Enterprise Linux version 5 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6 OpenVZ Project OpenVZ 042stab037.1 Linux kernel 3.0.1 Linux kernel 3.0-rc4-git1 Linux kernel 3.0-rc1 Linux kernel 3.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
OpenVZ Project OpenVZ 042stab039.10 |
Discussion
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
The Linux kernel is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected kernel to stop responding, therefore denying service to legitimate users.
The Linux kernel is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected kernel to stop responding, therefore denying service to legitimate users.
Exploit / POC
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
References:
References:
- [perf] overflow/perf_count_sw_cpu_clock crashes recent kernels (LKML)
- Bug 730706 - (CVE-2011-2918) CVE-2011-2918 kernel: perf: Fix software event over (Bugzilla)
- Download/kernel/rhel6/042stab039.10 (OpenVZ Project)
- Linux kernel Homepage (kernel.org)
- perf: Fix software event overflow (LKML)