PT-2010-3681 · Linux+2 · Linux Kernel+2

Eryu Guan

·

Published

2010-06-16

·

Updated

2018-10-10

·

CVE-2010-2070

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.4 through 4.0 Linux kernel version 2.6.18
Description The issue allows local users to cause a denial of service and modify the user mask of the PSR, effectively turning on BE. This can be achieved by exploiting a fault in the faults.c file when running on IA-64 architectures.
Recommendations For Xen versions 3.4 through 4.0, update to a version that includes the fix for this issue. For Linux kernel version 2.6.18, consider applying a patch or updating to a newer version that addresses this problem. As a temporary workaround, consider restricting access to the faults.c file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-2070
RHSA-2010:0610
RHSA-2010_0610

Affected Products

Linux Kernel
Red Hat
Xen