AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-4913

HIGH · CVSS 7.8 EPSS 4.18% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-06-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2011-4913
Severity
HIGH
CVSS
7.8
EPSS
4.18%
Linux

Original NVD Description

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.