5.5

CVE-2011-2498

The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.3.36 < 2.6.39
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

http://marc.info/?l=oss-security&m=130923704824984&w=2
Third Party Advisory
https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-2498.html
Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2011-2498
Third Party Advisory
https://usn.ubuntu.com/1167-1/
Third Party Advisory
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-1383-1
Third Party Advisory