CVE-2011-1022

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1022
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-1022.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-1022
Downstream
Related
Published
2011-03-22T17:55:01Z
Modified
2025-08-09T19:01:28Z
Summary
[none]
Details

The cgrereceivenetlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.

References

Affected packages