PT-2010-5691 · Suse+2 · Suse Linux Enterprise+2

Dan Rosenberg

·

Publicado

1970-01-01

·

Atualizado

2026-02-10

·

CVE-2010-3437

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-vmipae-debuginfo versions prior to 2.6.36-rc6 SUSE Linux Enterprise kernel-kdumppae-debuginfo versions prior to 2.6.36-rc6
Description The issue is related to multiple vulnerabilities in the Linux kernel, specifically an integer signedness error in the pkt find dev from minor function in drivers/block/pktcdvd.c. This error allows local users to obtain sensitive information from kernel memory or cause a denial of service via a crafted index value in a PKT CTRL CMD STATUS ioctl call. The vulnerabilities can be exploited remotely, potentially leading to a disruption of protected information.
Recommendations For SUSE Linux Enterprise kernel-vmipae-debuginfo versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue. For SUSE Linux Enterprise kernel-kdumppae-debuginfo versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue. As a temporary workaround, consider restricting access to the pktcdvd module to minimize the risk of exploitation.

Exploit

Correção

DoS

Information Disclosure

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04589
BDU:2015-04590
CVE-2010-3437
DSA-2126-1
ELSA-2011-0007
RHSA-2010:0842
RHSA-2010_0842

Produtos afetados

Linux Kernel
Red Hat
Suse Linux Enterprise