PT-2010-1037 · Linux+2 · Linux Kernel+2

·

CVE-2010-2803

·

Publicado

2010-08-20

·

Atualizado

2023-02-13

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions drbd-kmp-default versions (affected versions not specified) Linux kernel versions prior to 2.6.27.53 Linux kernel versions 2.6.32.x prior to 2.6.32.21 Linux kernel versions 2.6.34.x prior to 2.6.34.6 Linux kernel versions 2.6.35.x prior to 2.6.35.4
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The drm ioctl function in the Linux kernel's Direct Rendering Manager (DRM) subsystem allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
Recommendations For Linux kernel versions prior to 2.6.27.53, update to version 2.6.27.53 or later. For Linux kernel versions 2.6.32.x prior to 2.6.32.21, update to version 2.6.32.21 or later. For Linux kernel versions 2.6.34.x prior to 2.6.34.6, update to version 2.6.34.6 or later. For Linux kernel versions 2.6.35.x prior to 2.6.35.4, update to version 2.6.35.4 or later. As a temporary workaround for the drm ioctl function issue, consider restricting local access to the Direct Rendering Manager (DRM) subsystem until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05302
CVE-2010-2803
DSA-2094-1
RHSA-2010:0842
RHSA-2010_0842

Produtos afetados

Linux Kernel
Red Hat
Drbd-Kmp-Default