PT-2010-4077 · Linux+2 · Linux Kernel+2

Eugene Teo

·

Published

2010-08-05

·

Updated

2023-02-13

·

CVE-2010-2521

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.34-rc6
Description The issue is related to multiple buffer overflows in the XDR implementation in the NFS server, specifically in the fs/nfsd/nfs4xdr.c file. This can be exploited by remote attackers via a crafted NFSv4 compound WRITE request, potentially leading to a denial of service (panic) or possibly the execution of arbitrary code. The read buf and nfsd4 decode compound functions are involved in this issue.
Recommendations For Linux kernel versions prior to 2.6.34-rc6, update to version 2.6.34-rc6 or later to resolve the issue. As a temporary workaround, consider restricting access to the NFS server to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2010-2521
DSA-2094-1
RHSA-2010:0606
RHSA-2010:0610
RHSA-2010:0631
RHSA-2010:0893
RHSA-2010:0907
RHSA-2010_0606
RHSA-2010_0610

Affected Products

Linux Kernel
Red Hat
Suse