crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-4032 crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.
Ubuntu USN Ubuntu USN USN-1287-1 Linux (OMAP4) vulnerability
Ubuntu USN Ubuntu USN USN-1292-1 Linux kernel (Maverick backport) vulnerabilities
Ubuntu USN Ubuntu USN USN-1293-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1299-1 Linux kernel (EC2) vulnerabilities
Ubuntu USN Ubuntu USN USN-1301-1 Linux kernel (Natty backport) vulnerabilities
Ubuntu USN Ubuntu USN USN-1302-1 Linux kernel (OMAP4) vulnerabilities
Ubuntu USN Ubuntu USN USN-1303-1 Linux kernel (Marvell DOVE) vulnerabilities
Ubuntu USN Ubuntu USN USN-1304-1 Linux kernel (OMAP4) vulnerabilities
Ubuntu USN Ubuntu USN USN-1311-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1312-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1313-1 Linux Kernel (Oneiric backport) vulnerability
Ubuntu USN Ubuntu USN USN-1322-1 Linux kernel vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T23:53:32.660Z

Reserved: 2011-10-18T00:00:00Z

Link: CVE-2011-4081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-05-24T23:55:02.480

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-4081

cve-icon Redhat

Severity : Moderate

Publid Date: 2011-10-20T00:00:00Z

Links: CVE-2011-4081 - Bugzilla

cve-icon OpenCVE Enrichment

No data.