CVE-2011-0006: Low severity linux kernel vulnerability

Published Jan 7, 2011
·
Updated

If securityfilterruleinit() doesn't return a rule, then not everything is as fine as the return code implies. This bug only occurs when the LSM (eg. SELinux) is disabled at runtime.

Adding an empty LSM rule causes imamatchrules() to always succeed, ignoring any remaining rules. default IMA TCB policy: # PROCSUPERMAGIC dontmeasure fsmagic=0x9fa0 # SYSFSMAGIC dontmeasure fsmagic=0x62656572 # DEBUGFSMAGIC dontmeasure fsmagic=0x64626720 # TMPFSMAGIC dontmeasure fsmagic=0x01021994 # SECURITYFSMAGIC dontmeasure fsmagic=0x73636673 < LSM specific rule > dontmeasure objtype=varlogt measure func=BPRMCHECK measure func=FILEMMAP mask=MAYEXEC measure func=FILECHECK mask=MAYREAD uid=0 Thus without the patch, with the boot parameters 'tcb selinux=0', adding the above 'dontmeasure objtype=varlogt' rule to the default IMA TCB measurement policy, would result in nothing being measured. The patch prevents the default TCB policy from being replaced.

Upstream commit: http://git.kernel.org/linus/867c20265459d30a01b021a9c1e81fb4c5832aa9

Introduced in 2.6.30-rc1 4af4662f

Other sources

The imalsmruleinit function in security/integrity/ima/imapolicy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM.

Launchpad

Affected Software

5 affected components
debian/linux-2.6
Linux Linux kernel<=2.6.36.4
Linux Linux kernel=2.6.36.3
Linux Linux kernel=2.6.36.1
Linux Linux kernel=2.6.36.2

Event History

Jan 7, 2011
Data Sourced
via Red Hat·09:09 AM
DescriptionSeverityAffected Software
Jun 21, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:54 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:43 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-0006?

CVE-2011-0006 has a medium severity rating as it can cause improper access control under certain configurations.

2

How do I fix CVE-2011-0006?

To fix CVE-2011-0006, ensure that Linux Security Module (LSM) support is enabled at runtime.

3

What systems are affected by CVE-2011-0006?

CVE-2011-0006 affects various versions of the Linux kernel, specifically those prior to 2.6.37.

4

What impact does CVE-2011-0006 have on system security?

CVE-2011-0006 can lead to security flaws that bypass security rules, potentially allowing unauthorized actions.

5

Is there a patch available for CVE-2011-0006?

Yes, a patch for CVE-2011-0006 is included in Linux kernel version 2.6.37 and later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203