Back

MEDIUM

kernel: multiple issues in rose protocol

Published Jun 21, 2012

Description

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 21, 2012
Updated Aug 7, 2024
Reserved Dec 23, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 20, 2011