Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1006

22
FAUCET Score

CVE-2011-1006 describes a heap-based buffer overflow in the parse_cgroup_spec function within the Control Group Configuration Library (libcgroup) versions prior to 0.37.1. This vulnerability allows local users to potentially gain privileges by providing a specially crafted controller list to applications utilizing the library. With a CVSS score of 7.2, it is considered high severity, indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability, though it's unclear if it crosses privilege boundaries. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this decade-old vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.37CPE matchmatch criteria
cpe:2.3:a:balbir_singh:libcgroup:*:*:*:*:*:*:*:*
0.1bCPE matchmatch criteria
cpe:2.3:a:balbir_singh:libcgroup:0.1b:*:*:*:*:*:*:*
0.1cCPE matchmatch criteria
cpe:2.3:a:balbir_singh:libcgroup:0.1c:*:*:*:*:*:*:*
0.2CPE matchmatch criteria
cpe:2.3:a:balbir_singh:libcgroup:0.2:*:*:*:*:*:*:*
0.3CPE matchmatch criteria
cpe:2.3:a:balbir_singh:libcgroup:0.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 49th percentile among its peer group of 3,237 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libcgroup-0:0.36.1-6.el6_0.1
View patch

Vendor Advisories (1)

redhatCVE-2011-1006Important

libcgroup: Heap-based buffer overflow by converting list of controllers for given task into an array of strings

Mar 3, 2011

References

libcg.git.sourceforge.net / git/gitweb.cgi
lists.fedoraproject.org / pipermail/package-announce/2011-March/056683.html
lists.fedoraproject.org / pipermail/package-announce/2011-March/056734.html
lists.opensuse.org / opensuse-updates/2011-04/msg00027.html
bugzilla.redhat.com / show_bug.cgi
Patch
secunia.com / advisories/43611
Vendor Advisory
secunia.com / advisories/43758
Vendor Advisory
secunia.com / advisories/43891
secunia.com / advisories/44093
sourceforge.net / projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/download
Patch
debian.org / security/2011/dsa-2193
redhat.com / support/errata/RHSA-2011-0320.html
securityfocus.com / bid/46729
securitytracker.com / id
vupen.com / english/advisories/2011/0679
Vendor Advisory
vupen.com / english/advisories/2011/0774