PT-2010-5689 · Linux+2 · Linux Kernel+2
Tavis Ormandy
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2010-3067
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise (affected versions not specified)
kernel-vmipae-debuginfo (affected versions not specified)
kernel-kdumppae-debuginfo (affected versions not specified)
Linux kernel versions prior to 2.6.36-rc4-next-20100915
Description
The issue involves multiple vulnerabilities in the Linux kernel and related packages, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, an integer overflow in the
do io submit function in fs/aio.c allows local users to cause a denial of service or possibly have other unspecified impacts via crafted use of the io submit system call.Recommendations
For SUSE Linux Enterprise, kernel-vmipae-debuginfo, and kernel-kdumppae-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Linux kernel versions prior to 2.6.36-rc4-next-20100915, consider restricting access to the
io submit system call until a patch is available.DoS
Integer Overflow
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Suse Linux Enterprise