The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.
References
Link Providers
https://www.spirityenterprise.com/pentest spirity
https://www.spirityenterprise.com/managed-detection-response spirity
https://www.spirityenterprise.com/virtual-ciso spirity
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987 cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056683.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056734.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2011-04/msg00027.html cve-icon cve-icon
http://openwall.com/lists/oss-security/2011/02/25/11 cve-icon cve-icon
http://openwall.com/lists/oss-security/2011/02/25/12 cve-icon cve-icon
http://openwall.com/lists/oss-security/2011/02/25/14 cve-icon cve-icon
http://openwall.com/lists/oss-security/2011/02/25/6 cve-icon cve-icon
http://openwall.com/lists/oss-security/2011/02/25/9 cve-icon cve-icon
http://secunia.com/advisories/43611 cve-icon cve-icon
http://secunia.com/advisories/43758 cve-icon cve-icon
http://secunia.com/advisories/43891 cve-icon cve-icon
http://secunia.com/advisories/44093 cve-icon cve-icon
http://sourceforge.net/mailarchive/message.php?msg_id=26598749 cve-icon cve-icon
http://sourceforge.net/mailarchive/message.php?msg_id=27102603 cve-icon cve-icon
http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/download cve-icon cve-icon
http://www.debian.org/security/2011/dsa-2193 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0320.html cve-icon cve-icon
http://www.securityfocus.com/bid/46578 cve-icon cve-icon
http://www.securitytracker.com/id?1025157 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0679 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0774 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=680409 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2011-1022 cve-icon
https://www.cve.org/CVERecord?id=CVE-2011-1022 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T22:14:27.029Z

Reserved: 2011-02-14T00:00:00

Link: CVE-2011-1022

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-03-22T17:55:01.987

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-1022

cve-icon Redhat

Severity : Low

Publid Date: 2011-02-18T00:00:00Z

Links: CVE-2011-1022 - Bugzilla