CVE-2011-2906

Description

From CVE.org

Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.

Statement

Not a security issue as privileges equal to root are needed. This issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG.

Frequently Asked Questions

Want to get errata notifications? Sign up here.