PT-2010-5694 · Linux+2 · Linux Kernel+2
Dan Rosenberg
·
Published
1970-01-01
·
Updated
2020-08-13
·
CVE-2010-4081
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise (affected versions not specified)
Linux kernel versions prior to 2.6.36-rc6
Description
The issue concerns multiple vulnerabilities in the Linux kernel, specifically affecting the
snd hdspm hwdep ioctl function in sound/pci/rme9652/hdspm.c. These vulnerabilities can be exploited remotely and may lead to unauthorized access to sensitive information. Local users can obtain potentially sensitive information from kernel stack memory via an SNDRV HDSPM IOCTL GET CONFIG INFO ioctl call.Recommendations
For Linux kernel versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue.
At the moment, there is no information about a newer version of SUSE Linux Enterprise that contains a fix for this vulnerability.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Suse Linux Enterprise