PT-2010-5686 · Linux+2 · Linux Kernel+2

Petr Matousek

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2010-4157

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.36.1 kernel-kdumppae-debuginfo (affected versions not specified) kernel-devel-2.6.9 kernel-doc-2.6.9 kernel-hugemem-2.6.9 kernel-2.6.9 kernel-largesmp-2.6.9 kernel-smp-devel-2.6.9 kernel-smp-2.6.9 kernel-largesmp-devel-2.6.9 kernel-hugemem-devel-2.6.9 kernel-smp-devel-2.6.9 kernel-largesmp-devel-2.6.9
Description The issue is related to multiple vulnerabilities in the Linux kernel, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. A specific vulnerability is an integer overflow in the ioc general function in drivers/scsi/gdth.c, allowing local users to cause a denial of service or possibly have other impacts via a large argument in an ioctl call.
Recommendations For Linux kernel versions prior to 2.6.36.1, update to version 2.6.36.1 or later to resolve the issue. For kernel-kdumppae-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For kernel-devel-2.6.9, kernel-doc-2.6.9, kernel-hugemem-2.6.9, kernel-2.6.9, kernel-largesmp-2.6.9, kernel-smp-devel-2.6.9, kernel-smp-2.6.9, kernel-largesmp-devel-2.6.9, kernel-hugemem-devel-2.6.9, and kernel-smp-devel-2.6.9, consider disabling the vulnerable functions or restricting access to the affected kernel modules until a patch is available.

Exploit

DoS

Integer Overflow

Memory Corruption

Information Disclosure

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04589
BDU:2015-04590
BDU:2015-06240
BDU:2015-06252
BDU:2015-06256
BDU:2015-06261
BDU:2015-06262
BDU:2015-06266
BDU:2015-06267
BDU:2015-06270
BDU:2015-06271
BDU:2015-08630
BDU:2015-08631
BDU:2015-08632
BDU:2015-08633
BDU:2015-08634
BDU:2015-08635
BDU:2015-08636
BDU:2015-08637
BDU:2015-08638
CVE-2010-4157
DSA-2126-1
RHSA-2010:0958
RHSA-2011:0004
RHSA-2011:0162
RHSA-2011_0004
RHSA-2011_0162

Affected Products

Linux Kernel
Red Hat
Suse