CVE-2011-1479 is a double free vulnerability in the inotify subsystem of the Linux kernel before version 2.6.39, allowing local users to cause a denial of service (system crash) through failed file creation attempts. This vulnerability has a CVSS score of 4.7, indicating a medium severity, with a local attack vector requiring medium complexity to exploit, leading to a complete system availability impact. While not currently on the KEV list or actively exploited, public exploit code exists, specifically EDB-35600, demonstrating its potential for exploitation. Despite the existence of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.38.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.38:*:*:*:*:*:*:* | ||
2.6.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.38:rc1:*:*:*:*:*:* | ||
2.6.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.38:rc2:*:*:*:*:*:* | ||
2.6.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.38:rc3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.