kernel: net_ns: oom killer fires because of slow net_ns cleanup
Published Oct 10, 2011
7.5
HIGHCVSS 3.1
EPSS 17.85%
Description
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.
Affected products
No data.
Configuration 1
- ≤ 2.6.32
Configuration 2
- 6.0
- 2.0
Configuration 3
- 10.04
- 10.10
- 11.04
- 11.10
Configuration 4
- 5.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 4
kernel
Not affected
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise MRG 2
realtime-kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not include support for Network Namespaces. A future kernel update in Red Hat Enterprise MRG may address this issue. The risks associated with fixing this flaw outweigh the benefits of the fix, therefore Red Hat does not plan to fix this flaw in Red Hat Enterprise Linux 6.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 17.85% (0.17854) | 97.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.84% (0.17841) | 96.78th | v5 (v2026.06.15) |
| Aug 31, 2025 | 7.25% (0.07252) | 91.27th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.57% (0.10569) | 92.57th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.35% (0.08348) | 86.88th | v4 (v2025.03.14) |
| Mar 19, 2025 | 10.57% (0.10569) | 92.32th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.30% (0.09296) | 92.16th | v4 (v2025.03.14) |
| Mar 7, 2025 | 2.72% (0.02716) | 90.50th | v3 (v2023.03.01) |
| Dec 17, 2024 | 1.41% (0.01413) | 86.21th | v3 (v2023.03.01) |
| Oct 29, 2023 | 2.51% (0.02514) | 88.95th | v3 (v2023.03.01) |
| May 10, 2023 | 2.48% (0.02476) | 88.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.76% (0.01761) | 86.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
References (17)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629373 x_refsource_CONFIRMExploitMailing ListThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2b035b39970740722598f7a9d548835f9bdd730f x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f875bae065334907796da12523f9df85c89f5712 x_refsource_CONFIRM
- http://ie.archive.ubuntu.com/linux/kernel/v2.6/ChangeLog-2.6.33 x_refsource_CONFIRMBroken Link
- http://kerneltrap.org/mailarchive/git-commits-head/2009/12/8/15289 mailing-listx_refsource_MLISTBroken Link
- http://neil.brown.name/git?p=linux-2.6%3Ba=patch%3Bh=2b035b39970740722598f7a9d548835f9bdd730f x_refsource_CONFIRM
- http://patchwork.ozlabs.org/patch/88217/ x_refsource_CONFIRMMailing ListPatchThird Party Advisory
- http://www.debian.org/security/2011/dsa-2305 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.openwall.com/lists/oss-security/2011/06/06/10 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2011/06/06/20 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.ubuntu.com/usn/USN-1288-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2011-2189 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/linux/+bug/720095 x_refsource_CONFIRMExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=711134 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=711245 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2189
- https://www.cve.org/CVERecord?id=CVE-2011-2189
Change history (0)
No recorded changes yet.