CVE-2011-1022
Description
The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.
Risk Information
Base Score
5.5
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.042
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-0.36.1-6.el6_0.1.i686.rpm | Linux |
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-0.36.1-6.el6_0.1.x86_64.rpm | Linux |
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-devel-0.36.1-6.el6_0.1.i686.rpm | Linux |
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-devel-0.36.1-6.el6_0.1.x86_64.rpm | Linux |
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-pam-0.36.1-6.el6_0.1.i686.rpm | Linux |
| (RHSA-2011:0320) Important: libcgroup security update libcgroup-pam-0.36.1-6.el6_0.1.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234