PT-2010-1049 · Linux+2 · Linux Kernel+3

Rafal Wojtczuk

·

Published

2010-08-30

·

Updated

2023-02-13

·

CVE-2010-2240

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.27.52 Linux kernel versions 2.6.32.x prior to 2.6.32.19 Linux kernel versions 2.6.34.x prior to 2.6.34.4 Linux kernel versions 2.6.35.x prior to 2.6.35.2 Red Hat Enterprise Linux kernel versions 2.4.21
Description The issue is related to multiple vulnerabilities in the Linux kernel, which can be exploited remotely to disrupt the availability of protected information. The do anonymous page function in mm/memory.c does not properly separate the stack and the heap, allowing context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment.
Recommendations For Linux kernel versions prior to 2.6.27.52, update to version 2.6.27.52 or later. For Linux kernel versions 2.6.32.x prior to 2.6.32.19, update to version 2.6.32.19 or later. For Linux kernel versions 2.6.34.x prior to 2.6.34.4, update to version 2.6.34.4 or later. For Linux kernel versions 2.6.35.x prior to 2.6.35.2, update to version 2.6.35.2 or later. For Red Hat Enterprise Linux kernel versions 2.4.21, consider upgrading to a newer version of the kernel. At the moment, there is no information about a newer version that contains a fix for this vulnerability in Red Hat Enterprise Linux kernel versions 2.4.21.

Exploit

Fix

Improper Validation of Array Index

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2015-06103
BDU:2015-06104
BDU:2015-06105
BDU:2015-06106
BDU:2015-06107
BDU:2015-06108
BDU:2015-06109
BDU:2015-06110
BDU:2015-06111
CVE-2010-2240
DSA-2094-1
RHSA-2010:0631
RHSA-2010:0660
RHSA-2010:0661
RHSA-2010:0670
RHSA-2010:0676
RHSA-2010:0677
RHSA-2010:0882
RHSA-2010_0661
RHSA-2010_0676
SUSE-SU-2012_0640-1
SUSE-SU-2012_0644-1

Affected Products

Linux Kernel
Red Hat
Red Hat Enterprise Linux Kernel
Suse