CVE-2011-1474 describes a local denial-of-service (DoS) vulnerability affecting specific patched versions of the Linux kernel (2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch). This flaw stems from an incorrect bounds check within the arch_get_unmapped_area_topdown function, which can be triggered by a specific sequence of mmap calls. Successful exploitation leads to an infinite loop, consuming system resources and ultimately causing a system crash. Rated Medium severity (CVSS 5.5), this vulnerability requires local access and low privileges to execute, with no user interaction needed. The primary impact is a complete loss of system availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.32.33CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32.33:test79:*:*:*:*:*:* | ||
2.6.37.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37.4:test14:*:*:*:*:*:* | ||
2.6.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.38:test3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.