PT-2010-1056 · Centos+3 · Centos+3
Vegard Nossum
·
Publicado
2010-11-29
·
Atualizado
2023-02-13
·
CVE-2010-4249
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.9
Red Hat Enterprise Linux kernel versions 2.6.9
CentOS kernel versions 2.6.9
Description
The issue affects the Linux kernel and can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The wait for unix gc function in net/unix/garbage.c does not properly select times for garbage collection of inflight sockets, allowing local users to cause a denial of service via crafted use of the socketpair and sendmsg system calls for SOCK SEQPACKET sockets.
Recommendations
For Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
For Red Hat Enterprise Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
For CentOS kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
As a temporary workaround, consider restricting access to the vulnerable kernel functions until a patch is available.
Exploit
Correção
DoS
Memory Corruption
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat
Suse