VYPR
Unrated severityNVD Advisory· Published May 9, 2011· Updated Apr 29, 2026

CVE-2011-1598

CVE-2011-1598

Description

The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.

Affected products

7
  • Linux/Kernel7 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <2.6.39
    • cpe:2.3:o:linux:linux_kernel:2.6.39:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.39:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.39:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.39:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.39:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.39:rc5:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.