PT-2010-1056 · Centos+3 · Centos+3
Vegard Nossum
·
Published
2010-11-29
·
Updated
2023-02-13
·
CVE-2010-4249
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.9
Red Hat Enterprise Linux kernel versions 2.6.9
CentOS kernel versions 2.6.9
Description
The issue affects the Linux kernel and can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The wait for unix gc function in net/unix/garbage.c does not properly select times for garbage collection of inflight sockets, allowing local users to cause a denial of service via crafted use of the socketpair and sendmsg system calls for SOCK SEQPACKET sockets.
Recommendations
For Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
For Red Hat Enterprise Linux kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
For CentOS kernel version 2.6.9, update to a version after 2.6.37-rc3-next-20101125.
As a temporary workaround, consider restricting access to the vulnerable kernel functions until a patch is available.
Exploit
Fix
DoS
Memory Corruption
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat
Suse