PT-2010-5694 · Linux+2 · Linux Kernel+2

Dan Rosenberg

·

Published

1970-01-01

·

Updated

2020-08-13

·

CVE-2010-4081

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise (affected versions not specified) Linux kernel versions prior to 2.6.36-rc6
Description The issue concerns multiple vulnerabilities in the Linux kernel, specifically affecting the snd hdspm hwdep ioctl function in sound/pci/rme9652/hdspm.c. These vulnerabilities can be exploited remotely and may lead to unauthorized access to sensitive information. Local users can obtain potentially sensitive information from kernel stack memory via an SNDRV HDSPM IOCTL GET CONFIG INFO ioctl call.
Recommendations For Linux kernel versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue. At the moment, there is no information about a newer version of SUSE Linux Enterprise that contains a fix for this vulnerability.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04589
BDU:2015-04590
CVE-2010-4081
DSA-2126-1
RHSA-2011:0007
RHSA-2011:0017
RHSA-2011_0007
RHSA-2011_0017

Affected Products

Linux Kernel
Red Hat
Suse Linux Enterprise