PT-2001-2681 · Red Hat+2 · Kernel-Patch+7

Published

1970-01-01

·

Updated

2024-02-02

·

CVE-2001-1391

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image-2.2.19-amiga version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-atari version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-bvme6000 version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-chrp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-compact version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-generic version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-ide version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-idepci version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-jensen version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mac version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mvme147 version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mvme16x version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-nautilus version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-pmac version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-prep version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-smp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4cdm version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4dm-pci version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4dm-smp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4u version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4u-smp version 2.2.19 Red Hat Linux kernel-patch-2.2.19-m68k version 2.2.19 Red Hat Linux kernel-patch-2.2.19-powerpc version 2.2.19 Red Hat Linux losetup-2.10r-0.6.x version 2.10r-0.6.x Red Hat Linux losetup-2.10r-5 version 2.10r-5 Red Hat Linux mount-2.10r-0.6.x version 2.10r-0.6.x Red Hat Linux mount-2.10r-5 version 2.10r-5 Red Hat Linux nfs-utils-0.3.1 version 0.3.1
Description The issue affects multiple packages of Debian GNU/Linux and Red Hat Linux operating systems, allowing for remote exploitation that may lead to a breach of confidentiality, integrity, and availability of protected information. An off-by-one vulnerability in the CPIA driver of the Linux kernel before version 2.2.19 enables users to modify kernel memory.
Recommendations As a temporary workaround, consider disabling the CPIA driver until a patch is available. Restrict access to the kernel memory to minimize the risk of exploitation. Update the kernel to version 2.2.19 or later to resolve the issue. For each affected package, update to a version that is not vulnerable to the off-by-one vulnerability in the CPIA driver. For Red Hat Linux, update the losetup, mount, and nfs-utils packages to versions that are not vulnerable. For Debian GNU/Linux, update the kernel-image packages to versions that are not vulnerable.

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-03682
BDU:2015-03683
BDU:2015-03684
BDU:2015-03685
BDU:2015-03686
BDU:2015-03687
BDU:2015-03688
BDU:2015-03689
BDU:2015-03690
BDU:2015-03691
BDU:2015-03692
BDU:2015-03693
BDU:2015-03694
BDU:2015-03695
BDU:2015-03696
BDU:2015-03697
BDU:2015-03698
BDU:2015-03699
BDU:2015-03700
BDU:2015-03701
BDU:2015-03702
BDU:2015-03703
BDU:2015-03704
BDU:2015-03705
BDU:2015-03706
BDU:2015-03707
BDU:2015-03708
BDU:2015-03709
BDU:2015-08156
BDU:2015-08157
BDU:2015-08165
BDU:2015-08166
BDU:2015-08173
CVE-2001-1391

Affected Products

Debian
Linux Kernel
Red Hat
Kernel-Image
Kernel-Patch
Losetup
Mount
Nfs-Utils