CVE-2011-1020 describes a vulnerability in the Linux kernel, specifically affecting versions 2.6.37 and earlier, where the /proc filesystem fails to restrict access to a process's directory tree after it executes a setuid program. This flaw allows local users to access sensitive information or cause a denial of service. With a CVSS score of 4.6, it is considered a medium-severity local vulnerability, requiring low attack complexity and offering potential for partial confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog or showing active exploitation, an exploit demonstrating privilege escalation on Ubuntu 10.04 (kernel 2.6.32) is available on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.