PT-2010-1056 · Centos+3 · Centos+3

Vegard Nossum

·

Published

2010-11-29

·

Updated

2023-02-13

·

CVE-2010-4249

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.9 Red Hat Enterprise Linux kernel versions 2.6.9 CentOS kernel versions 2.6.9
Description The issue affects the Linux kernel and can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The wait for unix gc function in net/unix/garbage.c does not properly select times for garbage collection of inflight sockets, allowing local users to cause a denial of service via crafted use of the socketpair and sendmsg system calls for SOCK SEQPACKET sockets.
Recommendations For Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125. For Red Hat Enterprise Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125. For CentOS kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125. As a temporary workaround, consider restricting access to the vulnerable kernel functions until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2015-06240
BDU:2015-06252
BDU:2015-06256
BDU:2015-06261
BDU:2015-06262
BDU:2015-06266
BDU:2015-06267
BDU:2015-06270
BDU:2015-06271
BDU:2015-08630
BDU:2015-08631
BDU:2015-08632
BDU:2015-08633
BDU:2015-08634
BDU:2015-08635
BDU:2015-08636
BDU:2015-08637
BDU:2015-08638
CVE-2010-4249
DSA-2153-1
RHSA-2011:0007
RHSA-2011:0162
RHSA-2011:0303
RHSA-2011:0330
RHSA-2011_0007
RHSA-2011_0162
RHSA-2011_0303

Affected Products

Centos
Linux Kernel
Red Hat
Suse