CVE-2011-1767: Medium severity linux kernel vulnerability

Published May 5, 2011
·
Updated

Description: 1) CVE-2011-1767 gre: fix netns vs proto registration ordering

GRE protocol receive hook can be called right after protocol addition is done. If netns stuff is not yet initialized, we're going to oops in netgeneric().

This is remotely oopsable if ipgre is compiled as module and packet comes at unfortunate moment of module loading.

Upstream commit: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=c2892f02

References: http://www.openwall.com/lists/oss-security/2010/02/18/3 http://patchwork.ozlabs.org/patch/45553/

2) CVE-2011-1768 tunnels: fix netns vs proto registration ordering

Same stuff as in ipgre patch: receive hook can be called before netns setup is done, oopsing in netgeneric().

Upstream commit: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=d5aa407f

References: http://www.openwall.com/lists/oss-security/2010/02/18/3 http://patchwork.ozlabs.org/patch/45554/

Other sources

net/ipv4/ipgre.c in the Linux kernel before 2.6.34, when ipgre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

Launchpad

Affected Software

22 affected components
debian/linux-2.6
Linux Linux kernel=2.6.33.7
Linux Linux kernel=2.6.33.9
Linux Linux kernel=2.6.33.18
Linux Linux kernel=2.6.33.14
Linux Linux kernel=2.6.33.19
Linux Linux kernel=2.6.33.2
Linux Linux kernel=2.6.33.6
Linux Linux kernel=2.6.33.17
Linux Linux kernel=2.6.33.1
Linux Linux kernel=2.6.33.4
Linux Linux kernel=2.6.33
Linux Linux kernel=2.6.33.12
Linux Linux kernel=2.6.33.3
Linux Linux kernel=2.6.33.13
Linux Linux kernel=2.6.33.11
Linux Linux kernel=2.6.33.15
Linux Linux kernel=2.6.33.16
Linux Linux kernel<=2.6.33.20
Linux Linux kernel=2.6.33.8
Linux Linux kernel=2.6.33.5
Linux Linux kernel=2.6.33.10

Event History

May 5, 2011
Data Sourced
via Red Hat·10:22 AM
DescriptionSeverityAffected Software
Jun 13, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:24 AM
RemedyDescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·09:56 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:44 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-1767?

CVE-2011-1767 is rated as important due to potential system instability and kernel crashes.

2

How do I fix CVE-2011-1767?

To mitigate CVE-2011-1767, update the Linux kernel to version 2.6.33.20 or later.

3

What systems are affected by CVE-2011-1767?

CVE-2011-1767 affects multiple versions of the Linux kernel, specifically those earlier than 2.6.33.20.

4

What kind of vulnerability is CVE-2011-1767?

CVE-2011-1767 is a vulnerability that stems from improper initialization during network protocol registration.

5

Can CVE-2011-1767 cause denial of service?

Yes, CVE-2011-1767 can lead to denial of service if the kernel encounters instability or crashes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203