PT-2010-5697 · Suse+2 · Cpint-Kmp-Default+4
Brad Spengler
+1
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2010-2955
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.36-rc3-next-20100831
cpint-kmp-default (affected versions not specified)
cloop-kmp-default (affected versions not specified)
drbd-kmp-default (affected versions not specified)
Description
The issue allows local users to obtain potentially sensitive information from kernel heap memory due to an off-by-one error in the
ioctl standard iw point function. This can be achieved via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size. Multiple vulnerabilities in the cpint-kmp-default, cloop-kmp-default, and drbd-kmp-default packages of the SUSE Linux Enterprise and openSUSE operating systems can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.Recommendations
For Linux kernel versions prior to 2.6.36-rc3-next-20100831, update to a version after 2.6.36-rc3-next-20100831 to resolve the issue.
For cpint-kmp-default, cloop-kmp-default, and drbd-kmp-default, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Cloop-Kmp-Default
Cpint-Kmp-Default
Drbd-Kmp-Default