CVE-2011-1083 describes a denial-of-service vulnerability in the epoll implementation of Linux kernel versions 2.6.37.2 and earlier, affecting distributions like Red Hat and SUSE. A local attacker can exploit this by crafting an application that uses epoll_create and epoll_ctl system calls, leading to high CPU consumption. This vulnerability has a CVSS score of 4.9, indicating a low attack complexity and no authentication required, but it only allows for a denial of service. While not actively exploited in the wild and not on the CISA KEV catalog, a proof-of-concept exploit exists on ExploitDB, and there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.37.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:-:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:vmware:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.