PT-2010-5700 · Linux+2 · Linux Kernel+3
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2010-3081
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise cpint-kmp-default (affected versions not specified)
Red Hat Enterprise Linux kernel-smp-2.4.21
Red Hat Enterprise Linux kernel-source-2.4.21
Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21
Red Hat Enterprise Linux kernel-2.4.21
Red Hat Enterprise Linux kernel-doc-2.4.21
Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21
Red Hat Enterprise Linux kernel-BOOT-2.4.21
Red Hat Enterprise Linux kernel-unsupported-2.4.21
Red Hat Enterprise Linux kernel-hugemem-2.4.21
Linux kernel versions prior to 2.6.36-rc4-git2
Description
The issue involves multiple vulnerabilities in various Linux kernel packages, which can lead to disruptions in confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out locally or remotely, depending on the specific package and system configuration. In some cases, exploitation can allow local users to gain privileges. The compat alloc user space functions in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate userspace memory required for the 32-bit compatibility layer, which can be exploited to control a certain length value, related to a "stack pointer underflow" issue.
Recommendations
For SUSE Linux Enterprise cpint-kmp-default, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Red Hat Enterprise Linux kernel-smp-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-source-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-doc-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-BOOT-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-hugemem-2.4.21, consider updating to a version that is not vulnerable.
For Linux kernel versions prior to 2.6.36-rc4-git2, consider updating to version 2.6.36-rc4-git2 or later.
Exploit
Buffer Overflow
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Suse Linux Enterprise
Suse