First published: Wed Mar 02 2011(Updated: )
Description of problem: The epoll subsystem allows users to create large nested epoll structures, which the kernel will then to walk with preemption disabled, causing a denial of service via excessive CPU consumption in the kernel. References: <a href="http://thread.gmane.org/gmane.linux.kernel/1105744">http://thread.gmane.org/gmane.linux.kernel/1105744</a> <a href="http://thread.gmane.org/gmane.linux.kernel/1105744/focus=1105888">http://thread.gmane.org/gmane.linux.kernel/1105744/focus=1105888</a> <a href="http://seclists.org/oss-sec/2011/q1/337">http://seclists.org/oss-sec/2011/q1/337</a> Acknowledgements: Red Hat would like to thank Nelson Elhage for reporting this issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=2.6.37.2 | |
SUSE Linux Enterprise Server | =11-sp1 | |
SUSE Linux Enterprise Desktop | =11-sp1 | |
SUSE Linux Enterprise Desktop | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp1 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1083 is classified as a denial-of-service vulnerability due to excessive CPU consumption.
To mitigate CVE-2011-1083, users should update their Linux kernel to a version newer than 2.6.37.2.
CVE-2011-1083 affects Linux kernel versions up to and including 2.6.37.2.
CVE-2011-1083 can potentially be exploited locally as it requires the ability to create nested epoll structures.
CVE-2011-1083 impacts various distributions including SUSE Linux Enterprise Desktop and Server, as well as Red Hat Enterprise Linux.