PT-2010-5700 · Linux+2 · Linux Kernel+3

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-3081

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise cpint-kmp-default (affected versions not specified) Red Hat Enterprise Linux kernel-smp-2.4.21 Red Hat Enterprise Linux kernel-source-2.4.21 Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21 Red Hat Enterprise Linux kernel-2.4.21 Red Hat Enterprise Linux kernel-doc-2.4.21 Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21 Red Hat Enterprise Linux kernel-BOOT-2.4.21 Red Hat Enterprise Linux kernel-unsupported-2.4.21 Red Hat Enterprise Linux kernel-hugemem-2.4.21 Linux kernel versions prior to 2.6.36-rc4-git2
Description The issue involves multiple vulnerabilities in various Linux kernel packages, which can lead to disruptions in confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out locally or remotely, depending on the specific package and system configuration. In some cases, exploitation can allow local users to gain privileges. The compat alloc user space functions in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate userspace memory required for the 32-bit compatibility layer, which can be exploited to control a certain length value, related to a "stack pointer underflow" issue.
Recommendations For SUSE Linux Enterprise cpint-kmp-default, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Red Hat Enterprise Linux kernel-smp-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-source-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-doc-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-BOOT-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-unsupported-2.4.21, consider updating to a version that is not vulnerable. For Red Hat Enterprise Linux kernel-hugemem-2.4.21, consider updating to a version that is not vulnerable. For Linux kernel versions prior to 2.6.36-rc4-git2, consider updating to version 2.6.36-rc4-git2 or later.

Exploit

Buffer Overflow

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04609
BDU:2015-04610
BDU:2015-06103
BDU:2015-06104
BDU:2015-06105
BDU:2015-06106
BDU:2015-06107
BDU:2015-06108
BDU:2015-06109
BDU:2015-06110
BDU:2015-06111
CVE-2010-3081
DSA-2110-1
ELSA-2011-0007
OPENSUSE-SU-2024:10128-1
RHSA-2010:0704
RHSA-2010:0705
RHSA-2010:0711
RHSA-2010:0718
RHSA-2010:0719
RHSA-2010:0758
RHSA-2010:0842
RHSA-2010:0882
RHSA-2010_0704
RHSA-2010_0718
RHSA-2010_0842

Affected Products

Linux Kernel
Red Hat
Suse Linux Enterprise
Suse