PT-2010-5691 · Suse+2 · Suse Linux Enterprise+2
Dan Rosenberg
·
Publicado
1970-01-01
·
Atualizado
2026-02-10
·
CVE-2010-3437
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise kernel-vmipae-debuginfo versions prior to 2.6.36-rc6
SUSE Linux Enterprise kernel-kdumppae-debuginfo versions prior to 2.6.36-rc6
Description
The issue is related to multiple vulnerabilities in the Linux kernel, specifically an integer signedness error in the
pkt find dev from minor function in drivers/block/pktcdvd.c. This error allows local users to obtain sensitive information from kernel memory or cause a denial of service via a crafted index value in a PKT CTRL CMD STATUS ioctl call. The vulnerabilities can be exploited remotely, potentially leading to a disruption of protected information.Recommendations
For SUSE Linux Enterprise kernel-vmipae-debuginfo versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue.
For SUSE Linux Enterprise kernel-kdumppae-debuginfo versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
pktcdvd module to minimize the risk of exploitation.Exploit
Correção
DoS
Information Disclosure
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Suse Linux Enterprise