PT-2010-5689 · Linux+2 · Linux Kernel+2

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2010-3067

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise (affected versions not specified) kernel-vmipae-debuginfo (affected versions not specified) kernel-kdumppae-debuginfo (affected versions not specified) Linux kernel versions prior to 2.6.36-rc4-next-20100915
Description The issue involves multiple vulnerabilities in the Linux kernel and related packages, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, an integer overflow in the do io submit function in fs/aio.c allows local users to cause a denial of service or possibly have other unspecified impacts via crafted use of the io submit system call.
Recommendations For SUSE Linux Enterprise, kernel-vmipae-debuginfo, and kernel-kdumppae-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Linux kernel versions prior to 2.6.36-rc4-next-20100915, consider restricting access to the io submit system call until a patch is available.

DoS

Integer Overflow

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2015-04589
BDU:2015-04590
CVE-2010-3067
DSA-2126-1
RHSA-2010:0758
RHSA-2010:0779
RHSA-2010:0839
RHSA-2010_0779
RHSA-2010_0839
RHSA-2011:0007
RHSA-2011_0007

Affected Products

Linux Kernel
Red Hat
Suse Linux Enterprise