CVE-2011-2496: Integer Overflow

Published Jun 24, 2011
·
Updated

Integer overflow in the vmatoresize function in mm/mremap.c in the L ...

Other sources

The normal mmap paths all avoid creating a mapping where the pgoff inside the mapping could wrap around due to overflow. However, an expanding mremap() can take such a non-wrapping mapping and make it bigger and cause a wrapping condition. There is also another case where we expand mappings hiding in plain sight: the automatic stack expansion.

The wrapping condition can cause a BUGON() due to terminally confusing the vmapriotree code.

Upstream patches: 982134ba62618c2d69fbbbd166d0a11ee3b7e3d8 mremap a626ca6a656450e9f4df91d0dda238fff23285f4 stack expansion downwards 42c36f63ac1366ab0ecc2d5717821362c259f517 stack expansion upwards

References: http://www.spinics.net/lists/stable-commits/msg11385.html http://www.spinics.net/lists/linux-mm/msg17093.html http://groups.google.com/group/fa.linux.kernel/msg/9e43ab898c5e6d16

Acknowledgements:

Red Hat would like to thank Robert Swiecki for reporting this issue.

Red Hat

Affected Software

18 affected components
Linux Linux kernel=2.6.38-rc7
Linux Linux kernel=2.6.38-rc6
Linux Linux kernel=2.6.38-rc4
Linux Linux kernel=2.6.38.3
Linux Linux kernel<=2.6.38.8
Linux Linux kernel=2.6.38-rc3
Linux Linux kernel=2.6.38-rc5
Linux Linux kernel=2.6.38-rc2
Linux Linux kernel=2.6.38.6
Linux Linux kernel=2.6.38.1
Linux Linux kernel=2.6.38-rc1
Linux Linux kernel=2.6.38.5
Linux Linux kernel=2.6.38.2
Linux Linux kernel=2.6.38
Linux Linux kernel=2.6.38-rc8
Linux Linux kernel=2.6.38.4
Linux Linux kernel=2.6.38.7
debian/linux-2.6

Event History

Jun 24, 2011
Data Sourced
via Red Hat·08:10 PM
DescriptionSeverityAffected Software
Jun 13, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 15, 2024
Data Sourced
via Launchpad·09:58 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·12:42 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·01:11 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-2496?

CVE-2011-2496 has been classified as high severity due to the potential for denial of service and system crashes.

2

How can I fix CVE-2011-2496?

To fix CVE-2011-2496, you should upgrade to a patched version of the Linux kernel that is not vulnerable, specifically version 2.6.39 or later.

3

Who is affected by CVE-2011-2496?

CVE-2011-2496 affects local users of the Linux kernel versions before 2.6.39.

4

What type of attack does CVE-2011-2496 enable?

CVE-2011-2496 enables a denial of service attack that can lead to a system crash through a crafted mremap system call.

5

What versions of the Linux kernel are vulnerable to CVE-2011-2496?

Linux kernel versions before 2.6.39, including 2.6.38 and earlier release candidates, are vulnerable to CVE-2011-2496.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203