{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2011-2189", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[git-commits-head] 20091208 net: Automatically allocate per namespace data.", "refsource" : "MLIST", "url" : "http://kerneltrap.org/mailarchive/git-commits-head/2009/12/8/15289" }, { "name" : "[oss-security] 20110606 Re: CVE Request -- vsftpd -- Do not create network namespace per connection", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2011/06/06/10" }, { "name" : "[oss-security] 20110606 Re: CVE Request -- vsftpd -- Do not create network namespace per connection", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2011/06/06/20" }, { "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629373", "refsource" : "CONFIRM", "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629373" }, { "name" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2b035b39970740722598f7a9d548835f9bdd730f", "refsource" : "CONFIRM", "url" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2b035b39970740722598f7a9d548835f9bdd730f" }, { "name" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f875bae065334907796da12523f9df85c89f5712", "refsource" : "CONFIRM", "url" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f875bae065334907796da12523f9df85c89f5712" }, { "name" : "http://ie.archive.ubuntu.com/linux/kernel/v2.6/ChangeLog-2.6.33", "refsource" : "CONFIRM", "url" : "http://ie.archive.ubuntu.com/linux/kernel/v2.6/ChangeLog-2.6.33" }, { "name" : "http://neil.brown.name/git?p=linux-2.6;a=patch;h=2b035b39970740722598f7a9d548835f9bdd730f", "refsource" : "CONFIRM", "url" : "http://neil.brown.name/git?p=linux-2.6;a=patch;h=2b035b39970740722598f7a9d548835f9bdd730f" }, { "name" : "http://patchwork.ozlabs.org/patch/88217/", "refsource" : "CONFIRM", "url" : "http://patchwork.ozlabs.org/patch/88217/" }, { "name" : "https://bugs.launchpad.net/ubuntu/+source/linux/+bug/720095", "refsource" : "CONFIRM", "url" : "https://bugs.launchpad.net/ubuntu/+source/linux/+bug/720095" }, { "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=711134", "refsource" : "CONFIRM", "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=711134" }, { "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=711245", "refsource" : "CONFIRM", "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=711245" }, { "name" : "DSA-2305", "refsource" : "DEBIAN", "url" : "http://www.debian.org/security/2011/dsa-2305" }, { "name" : "USN-1288-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1288-1" } ] } }