Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel inet_diag.c文件资源管理错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 2.6.37-rc2之前版本中的net/ipv4/inet_diag.c文件没有正确审计INET_DIAG字节码。本地用户可以借助包含多个属性元素的网络连接消息中的特制INET_DIAG_REQ_BYTECODE指令导致拒绝服务(内核死循环)。该漏洞已经通过INET_DIAG_BC_JMP指令得到证实。
CVSS Information
N/A
Vulnerability Type
N/A