PT-2010-5678 · Linux+2 · Linux Kernel+3

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-2942

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-vmipae-debuginfo (affected versions not specified) SUSE Linux Enterprise kernel-kdumppae-debuginfo (affected versions not specified) openSUSE drbd-kmp-default (affected versions not specified) Linux kernel versions prior to 2.6.36-rc2
Description The issue concerns multiple vulnerabilities in various packages of SUSE Linux Enterprise and openSUSE operating systems, as well as the Linux kernel. These vulnerabilities can be exploited to compromise the confidentiality, integrity, and availability of protected information. Exploitation can be performed remotely in the case of SUSE Linux Enterprise kernel-vmipae-debuginfo and kernel-kdumppae-debuginfo packages, and locally for the openSUSE drbd-kmp-default package. The Linux kernel vulnerability allows local users to obtain potentially sensitive information from kernel memory via certain dump operations related to network queueing functionality, specifically through functions such as tcf gact dump, tcf mirred dump, tcf nat dump, tcf simp dump, and tcf skbedit dump in various files under net/sched.
Recommendations For SUSE Linux Enterprise kernel-vmipae-debuginfo, consider restricting access to sensitive information until a patch is available. For SUSE Linux Enterprise kernel-kdumppae-debuginfo, restrict access to sensitive information until a patch is available. For openSUSE drbd-kmp-default, consider disabling local access to sensitive information until a patch is available. For Linux kernel versions prior to 2.6.36-rc2, update to a version 2.6.36-rc2 or later to resolve the issue. At the moment, there is no information about a newer version that contains a fix for the SUSE Linux Enterprise and openSUSE vulnerabilities.

Fix

Information Disclosure

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04589
BDU:2015-04590
BDU:2015-05302
CVE-2010-2942
OPENSUSE-SU-2024:10128-1
RHSA-2010:0723
RHSA-2010:0771
RHSA-2010:0779
RHSA-2010_0723
RHSA-2010_0779

Affected Products

Linux Kernel
Red Hat
Suse Linux Enterprise
Opensuse