CVE-2011-4604: Buffer Overflow

Published Dec 14, 2011
·
Updated

Don't write more than the requested number of bytes of an batman-adv icmp packet to the userspace buffer. Otherwise unrelated userspace memory might get overwritten by the kernel.

https://lists.open-mesh.org/pipermail/b.a.t.m.a.n/2011-December/005908.html

Statement:

Not vulnerable. This issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG as they did not include support for the BATMAN (Better Approach To Mobile Ad-hoc Networking) out-of-tree kernel module.

Acknowledgements:

Red Hat would like to thank Paul Kot for reporting this issue.

Other sources

The batsocketread function in net/batman-adv/icmpsocket.c in the Linux kernel before 3.3 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted batman-adv ICMP packet.

MITRE

Affected Software

55 affected components
Linux Linux kernel=3.2.21
Linux Linux kernel=3.2.19
Linux Linux kernel=3.2.23
Linux Linux kernel=3.2.44
Linux Linux kernel=3.2.18
Linux Linux kernel=3.2.5
Linux Linux kernel=3.2.26
Linux Linux kernel=3.2.40
Linux Linux kernel=3.2.37
Linux Linux kernel=3.2-rc2
Linux Linux kernel=3.2.16
Linux Linux kernel=3.2-rc5
Linux Linux kernel=3.2.27
Linux Linux kernel=3.2-rc4
Linux Linux kernel=3.2.11
Linux Linux kernel=3.2.32
Linux Linux kernel=3.2.34
Linux Linux kernel=3.2.10
Linux Linux kernel=3.2.14
Linux Linux kernel=3.2.29
Linux Linux kernel=3.2.43
Linux Linux kernel=3.2.31
Linux Linux kernel=3.2.25
Linux Linux kernel=3.2.4
Linux Linux kernel=3.2.41
Linux Linux kernel=3.2.9
Linux Linux kernel=3.2.15
Linux Linux kernel=3.2.20
Linux Linux kernel=3.2.24
Linux Linux kernel=3.2.6
Linux Linux kernel=3.2.2
Linux Linux kernel=3.2.39
Linux Linux kernel=3.2.42
Linux Linux kernel=3.2-rc3
Linux Linux kernel=3.2.13
Linux Linux kernel=3.2.1
Linux Linux kernel=3.2.7
Linux Linux kernel=3.2
Linux Linux kernel=3.2.30
Linux Linux kernel=3.2.45
Linux Linux kernel<=3.2.46
Linux Linux kernel=3.2.38
Linux Linux kernel=3.2.33
Linux Linux kernel=3.2.22
Linux Linux kernel=3.2-rc6
Linux Linux kernel=3.2.17
Linux Linux kernel=3.2-rc7
Linux Linux kernel=3.2.8
Linux Linux kernel=3.2
Linux Linux kernel=3.2.1
Linux Linux kernel=3.2.35
Linux Linux kernel=3.2.36
Linux Linux kernel=3.2.12
Linux Linux kernel=3.2.28
Linux Linux kernel=3.2.3

Event History

Dec 14, 2011
Data Sourced
08:22 AM
DescriptionSeverityAffected Software
Jun 7, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-4604?

The severity of CVE-2011-4604 is rated as high due to the potential for memory corruption in the Linux kernel.

2

How do I fix CVE-2011-4604?

To fix CVE-2011-4604, update the Linux kernel to a version higher than 3.2.46.

3

What systems are affected by CVE-2011-4604?

CVE-2011-4604 affects multiple versions of the Linux kernel, specifically versions 3.2 and below.

4

What type of vulnerability is CVE-2011-4604?

CVE-2011-4604 is a memory corruption vulnerability that could allow malicious userspace memory to be overwritten by the kernel.

5

Can CVE-2011-4604 lead to system compromise?

Yes, CVE-2011-4604 could potentially lead to a system compromise if exploited, allowing unauthorized access or control.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203