Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux SE 1.5
Astra Linux SE 1.6
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:ru.altx-soft.nix:def:14148
[Eng]
Version
12
Class
patch
ALTXid
27280
Language
Russian
Severity
Critical
Title
Обновление USN-1167-1 -- уязвимости linux
Description
linux: Linux kernel Multiple kernel flaws have been fixed.
Family
unix
Platform
Ubuntu 11.04
Product
linux
Reference
VENDOR: USN-1167-1
VENDOR: USN-1167-1
Id:
USN-1167-1
Reference:
https://usn.ubuntu.com/usn/usn-1167-1
CVE: CVE-2011-1747
CVE: CVE-2011-1747
Id:
CVE-2011-1747
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1747
Comment
: The agp subsystem in the Linux kernel 2.6.38.5 and earlier does not properly restrict memory allocation by the (1) AGPIOC_RESERVE and (2) AGPIOC_ALLOCATE ioctls, which allows local users to cause a denial of service (memory consumption) by making many calls to these ioctls.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
[linux-kernel] 20110414 [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
1025441 (SECTRACK)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698999 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
47832 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b522f02184b413955f3bc952e3776ce41edc6355 (MISC)
CVE: CVE-2011-1182
CVE: CVE-2011-1182
Id:
CVE-2011-1182
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182
Comment
: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=690028 (CONFIRM)
https://github.com/torvalds/linux/commit/da48524eb20662618854bb3df2db01fc65f3070c (CONFIRM)
[oss-security] 20110323 Re: Linux kernel signal spoofing vulnerability (CVE request) (MLIST)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=da48524eb20662618854bb3df2db01fc65f3070c (MISC)
CVE: CVE-2011-1169
CVE: CVE-2011-1169
Id:
CVE-2011-1169
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1169
Comment
: Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
129 (Improper Validation of Array Index)
References:
[oss-security] 20110318 Re: CVE request: kernel: AudioScience HPI driver (MLIST)
[oss-security] 20110318 CVE request: kernel: AudioScience HPI driver (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=688898 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.1 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=4a122c10fbfe9020df469f0f669da129c5757671 (MISC)
CVE: CVE-2011-1163
CVE: CVE-2011-1163
Id:
CVE-2011-1163
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163
Comment
: The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=688021 (CONFIRM)
1025225 (SECTRACK)
[oss-security] 20110315 Re: CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
[oss-security] 20110315 CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-02.txt (MISC)
[mm-commits] 20110314 + fs-partitions-osfc-corrupted-osf-partition-table-can-cause-information-disclosure.patch added to -mm tree (MLIST)
20110317 [PRE-SA-2011-02] Information disclosure vulnerability in the OSF partition handling code of the Linux kernel (BUGTRAQ)
46878 (BID)
8189 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1eafbfeb7bdf59cfe173304c76188f3fd5f1fd05 (MISC)
CVE: CVE-2011-1090
CVE: CVE-2011-1090
Id:
CVE-2011-1090
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090
Comment
: The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=682641 (CONFIRM)
[oss-security] 20110307 Re: CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
1025336 (SECTRACK)
[oss-security] 20110307 CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9e3d724e2145f5039b423c290ce2b2c3d8f94bc (MISC)
CVE: CVE-2011-1083
CVE: CVE-2011-1083
Id:
CVE-2011-1083
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083
Comment
: The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[linux-kernel] 20110225 [PATCH] optimize epoll loop detection (MLIST)
[oss-security] 20110302 Re: CVE request: kernel: Multiple DoS issues in epoll (MLIST)
[linux-kernel] 20110228 Re: [PATCH] optimize epoll loop detection (MLIST)
[oss-security] 20110301 CVE request: kernel: Multiple DoS issues in epoll (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681578 (CONFIRM)
43522 (SECUNIA)
71265 (OSVDB)
[linux-kernel] 20110226 Re: [PATCH] optimize epoll loop detection (MLIST)
RHSA-2012:0862 (REDHAT)
48898 (SECUNIA)
48964 (SECUNIA)
SUSE-SU-2012:0616 (SUSE)
SUSE-SU-2012:0554 (SUSE)
48410 (SECUNIA)
48115 (SECUNIA)
CVE: CVE-2011-1082
CVE: CVE-2011-1082
Id:
CVE-2011-1082
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082
Comment
: fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20110301 CVE request: kernel: Multiple DoS issues in epoll (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681575 (CONFIRM)
[oss-security] 20110302 Re: CVE request: kernel: Multiple DoS issues in epoll (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[linux-kernel] 20110205 [PATCH] epoll: Prevent deadlock through unsafe ->f_op->poll() calls. (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e (MISC)
CVE: CVE-2011-1076
CVE: CVE-2011-1076
Id:
CVE-2011-1076
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1076
Comment
: net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, which triggers improper handling of error data within a DNS resolver key.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[oss-security] 20110304 CVE-2011-1076 kernel: DNS: Fix a NULL pointer deref when trying to read an error key (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
1025162 (SECTRACK)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1362fa078dae16776cd439791c6605b224ea6171 (MISC)
CVE: CVE-2011-1019
CVE: CVE-2011-1019
Id:
CVE-2011-1019
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019
Comment
: The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
References:
https://github.com/torvalds/linux/commit/8909c9ad8ff03611c9c96c9a92656213e4bb495b (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: CAP_SYS_MODULE bypass via CAP_NET_ADMIN (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680360 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8909c9ad8ff03611c9c96c9a92656213e4bb495b (MISC)
CVE: CVE-2011-1016
CVE: CVE-2011-1016
Id:
CVE-2011-1016
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016
Comment
: The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
46557 (BID)
[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680000 (CONFIRM)
kernel-atiradeon-sec-bypass(65691) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef (MISC)
CVE: CVE-2011-1013
CVE: CVE-2011-1013
Id:
CVE-2011-1013
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013
Comment
: Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via a crafted num_crtcs (aka vb_num) structure member in an ioctl argument.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c (CONFIRM)
47639 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=679925 (CONFIRM)
kernel-drmioctl-priv-escalation(67199) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1922756124ddd53846877416d92ba4a802bc658f (MISC)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c.diff?r1=1.41%3Br2=1.42%3Bf=h (MISC)
CVE: CVE-2011-1012
CVE: CVE-2011-1012
Id:
CVE-2011-1012
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1012
Comment
: The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
369 (Divide By Zero)
References:
[mm-commits] 20110222 + ldm-corrupted-partition-table-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110223 CVE request: kernel: Corrupted LDM partition table issues (MLIST)
[oss-security] 20110223 Re: CVE request: kernel: Corrupted LDM partition table issues (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git6.log (CONFIRM)
1025127 (SECTRACK)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=294f6cf48666825d23c9372ef37631232746e40d (MISC)
CVE: CVE-2011-1010
CVE: CVE-2011-1010
Id:
CVE-2011-1010
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010
Comment
: Buffer overflow in the mac_partition function in fs/partitions/mac.c in the Linux kernel before 2.6.37.2 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via a malformed Mac OS partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=679282 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37.2 (CONFIRM)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
[oss-security] 20110222 CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
1025126 (SECTRACK)
46492 (BID)
8115 (SREASON)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-map-dos(65643) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa7ea87a057958a8b7926c1a60a3ca6d696328ed (MISC)
CVE: CVE-2011-0999
CVE: CVE-2011-0999
Id:
CVE-2011-0999
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0999
Comment
: mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact via a crafted application.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 (CONFIRM)
[oss-security] 20110217 Re: CVE request - kernel: thp: prevent hugepages during args/env copying into the user stack (MLIST)
46442 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=678209 (CONFIRM)
[oss-security] 20110217 CVE request - kernel: thp: prevent hugepages during args/env copying into the user stack (MLIST)
kernel-hugepages-dos(65535) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a7d6e4ecdb7648478ddec76d30d87d03d6e22b31 (MISC)
CVE: CVE-2011-0726
CVE: CVE-2011-0726
Id:
CVE-2011-0726
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726
Comment
: The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110311 [PATCH] proc: protect mm start_code/end_code in /proc/pid/stat (MLIST)
[mm-commits] 20110314 + proc-protect-mm-start_code-end_code-in-proc-pid-stat.patch added to -mm tree (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=684569 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.39/ChangeLog-2.6.39-rc1 (CONFIRM)
47791 (BID)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5883f57ca0008ffc93e09cbb9847a1928e50c6f3 ()
CVE: CVE-2011-0712
CVE: CVE-2011-0712
Id:
CVE-2011-0712
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712
Comment
: Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20110216 kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.38-rc4-next-20110215.bz2 (CONFIRM)
46419 (BID)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=677881 (CONFIRM)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
USN-1146-1 (UBUNTU)
kernel-usbdevice-bo(65461) (XF)
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=eaae55dac6b64c0616046436b294e69fc5311581 (MISC)
CVE: CVE-2011-0711
CVE: CVE-2011-0711
Id:
CVE-2011-0711
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711
Comment
: The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=677260 (CONFIRM)
46417 (BID)
[oss-security] 20110216 Re: CVE request - kernel: xfs infoleak (MLIST)
[oss-security] 20110216 CVE request - kernel: xfs infoleak (MLIST)
https://patchwork.kernel.org/patch/555461/ (CONFIRM)
70950 (OSVDB)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git3.log (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3a3675b7f23f83ca8c67c9c2b6edf707fd28d1ba (MISC)
CVE: CVE-2011-0695
CVE: CVE-2011-0695
Id:
CVE-2011-0695
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695
Comment
: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[linux-rdma] 20110223 [PATCH 2/2] ib/cm: Bump reference count on cm_id before invoking callback (MLIST)
43693 (SECUNIA)
46839 (BID)
[linux-rdma] 20110223 [PATCH 1/2] rdma/cm: Fix crash in request handlers (MLIST)
[oss-security] 20110311 CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler (MLIST)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-infiniband-dos(66056) (XF)
CVE: CVE-2011-0521
CVE: CVE-2011-0521
Id:
CVE-2011-0521
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521
Comment
: The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc2 (CONFIRM)
[oss-security] 20110125 Re: Linux kernel av7110 negative array offset (MLIST)
43009 (SECUNIA)
[oss-security] 20110125 Linux kernel av7110 negative array offset (MLIST)
45986 (BID)
1025195 (SECTRACK)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-av7110ca-privilege-escalation(64988) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb26a24ee9706473f31d34cc259f4dcf45cd0644 (MISC)
CVE: CVE-2011-1044
CVE: CVE-2011-1044
Id:
CVE-2011-1044
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1044
Comment
: The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=667916 (CONFIRM)
46488 (BID)
RHSA-2011:0927 (REDHAT)
kernel-ibuverbspollcq-info-disclosure(65563) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7182afea8d1afd432a17c18162cc3fd441d0da93 ()
CVE: CVE-2010-4649
CVE: CVE-2010-4649
Id:
CVE-2010-4649
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649
Comment
: Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
46073 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=667916 (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7182afea8d1afd432a17c18162cc3fd441d0da93 (MISC)
CVE: CVE-2010-4565
CVE: CVE-2010-4565
Id:
CVE-2010-4565
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565
Comment
: The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101220 CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101110 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101109 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101102 [SECURITY] CAN info leak/minor heap overflow (MLIST)
[oss-security] 20101104 Re: CVE request: kernel: CAN information leak (MLIST)
[oss-security] 20101103 CVE request: kernel: CAN information leak (MLIST)
44661 (BID)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101102 Re: [SECURITY] CAN info leak/minor heap overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=664544 (MISC)
MDVSA-2011:029 (MANDRIVA)
CVE: CVE-2010-4529
CVE: CVE-2010-4529
Id:
CVE-2010-4529
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4529
Comment
: Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
[oss-security] 20110103 Re: CVE request: kernel: irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
42684 (SECUNIA)
[oss-security] 20101223 CVE request: kernel: irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
[netdev] 20101222 [PATCH] irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
45556 (BID)
SUSE-SA:2011:008 (SUSE)
43291 (SECUNIA)
ADV-2011-0375 (VUPEN)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fdac1e0697356ac212259f2147aa60c72e334861 ()
CVE: CVE-2010-4527
CVE: CVE-2010-4527
Id:
CVE-2010-4527
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4527
Comment
: The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20101230 CVE request: kernel: buffer overflow in OSS load_mixer_volumes (MLIST)
45629 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=667615 (CONFIRM)
http://xorl.wordpress.com/2011/01/09/cve-2010-4527-linux-kernel-oss-sound-card-driver-buffer-overflow/ (MISC)
[oss-security] 20101231 Re: CVE request: kernel: buffer overflow in OSS load_mixer_volumes (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
42765 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
43291 (SECUNIA)
ADV-2011-0375 (VUPEN)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d81a12bc29ae4038770e05dce4ab7f26fd5880fb (MISC)
CVE: CVE-2010-4346
CVE: CVE-2010-4346
Id:
CVE-2010-4346
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4346
Comment
: The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE:
476 (NULL Pointer Dereference)
References:
[oss-security] 20101209 [taviso@cmpxchg8b.com: [PATCH] install_special_mapping skips security_file_mmap check.] (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc6 (CONFIRM)
42570 (SECUNIA)
[oss-security] 20101210 Re: Subject: CVE request: kernel: install_special_mapping skips security_file_mmap check (MLIST)
[linux-kernel] 20101209 [PATCH] install_special_mapping skips security_file_mmap check. (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=662189 (CONFIRM)
[oss-security] 20101210 Subject: CVE request: kernel: install_special_mapping skips security_file_mmap check (MLIST)
[oss-security] 20101209 Re: [taviso@cmpxchg8b.com: [PATCH] install_special_mapping skips security_file_mmap check.] (MLIST)
45323 (BID)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=462e635e5b73ba9a4c03913b77138cd57ce4b050 (MISC)
CVE: CVE-2010-4342
CVE: CVE-2010-4342
Id:
CVE-2010-4342
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4342
Comment
: The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending an Acorn Universal Networking (AUN) packet over UDP.
CVSSv2 Score:
7.1
Access vector:
NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[oss-security] 20101208 CVE request: kernel: NULL pointer dereference in AF_ECONET (MLIST)
[oss-security] 20101209 Re: CVE request: kernel: NULL pointer dereference in AF_ECONET (MLIST)
[netdev] 20101209 NULL dereference in econet AUN-over-UDP receive (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc6 (CONFIRM)
[netdev] 20101209 Re: NULL dereference in econet AUN-over-UDP receive (MLIST)
45321 (BID)
ADV-2011-0375 (VUPEN)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e085e76cbe558b79b54cbab772f61185879bc64 (MISC)
CVE: CVE-2010-4258
CVE: CVE-2010-4258
Id:
CVE-2010-4258
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4258
Comment
: The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
CVSSv2 Score:
6.2
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE:
269 (Improper Privilege Management)
References:
[oss-security] 20101209 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
[oss-security] 20101208 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
[oss-security] 20101202 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
20101207 Linux kernel exploit (FULLDISC)
[oss-security] 20101202 CVE request: kernel: failure to revert address limit override in OOPS error path (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=659567 (CONFIRM)
[linux-kernel] 20101201 [PATCH v2] do_exit(): Make sure we run with get_fs() == USER_DS. (MLIST)
http://blog.nelhage.com/2010/12/cve-2010-4258-from-dos-to-privesc/ (MISC)
[oss-security] 20101209 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
[oss-security] 20101208 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
[oss-security] 20101202 Re: CVE request: kernel: failure to revert address limit override in OOPS error path (MLIST)
[oss-security] 20101208 Re: kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
[linux-kernel] 20101201 Re: [PATCH v2] do_exit(): Make sure we run with get_fs() == USER_DS. (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
[oss-security] 20101202 kernel: Dangerous interaction between clear_child_tid, set_fs(), and kernel oopses (MLIST)
FEDORA-2010-18983 (FEDORA)
42745 (SECUNIA)
ADV-2010-3321 (VUPEN)
SUSE-SA:2011:002 (SUSE)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
42801 (SECUNIA)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
ADV-2011-0213 (VUPEN)
SUSE-SA:2011:005 (SUSE)
43056 (SECUNIA)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:008 (SUSE)
43291 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.html (CONFIRM)
http://code.google.com/p/chromium-os/issues/detail?id=10234 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=33dd94ae1ccbfb7bf0fb6c692bc3d1c4269e6177 (MISC)
CVE: CVE-2010-4256
CVE: CVE-2010-4256
Id:
CVE-2010-4256
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4256
Comment
: The pipe_fcntl function in fs/pipe.c in the Linux kernel before 2.6.37 does not properly determine whether a file is a named pipe, which allows local users to cause a denial of service via an F_SETPIPE_SZ fcntl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20101130 Re: CVE request: kernel: pipe_fcntl local DoS (MLIST)
[oss-security] 20101130 CVE request: kernel: pipe_fcntl local DoS (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c66fb347946ebdd5b10908866ecc9fa05ee2cf3d (MISC)
CVE: CVE-2010-4249
CVE: CVE-2010-4249
Id:
CVE-2010-4249
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4249
Comment
: The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101124 CVE request: kernel: unix socket local dos (MLIST)
[oss-security] 20101124 Re: CVE request: kernel: unix socket local dos (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.37-rc3-next-20101125.bz2 (CONFIRM)
[netdev] 20101124 [PATCH] af_unix: limit unix_tot_inflight (MLIST)
45037 (BID)
[linux-kernel] 20101124 [PATCH net-next-2.6] scm: lower SCM_MAX_FD (MLIST)
[linux-kernel] 20101125 Simple kernel attack using socketpair. easy, 100% reproductiblle, works under guest. no way to protect :( (MLIST)
15622 (EXPLOIT-DB)
https://bugzilla.redhat.com/show_bug.cgi?id=656756 (CONFIRM)
[linux-kernel] 20101123 Unix socket local DOS (OOM) (MLIST)
42354 (SECUNIA)
FEDORA-2010-18983 (FEDORA)
ADV-2010-3321 (VUPEN)
42745 (SECUNIA)
RHSA-2011:0162 (REDHAT)
42963 (SECUNIA)
ADV-2011-0168 (VUPEN)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=9915672d41273f5b77f1b3c29b391ffb7732b84b (MISC)
CVE: CVE-2010-4248
CVE: CVE-2010-4248
Id:
CVE-2010-4248
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4248
Comment
: Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[oss-security] 20101124 Re: CVE request: kernel: posix-cpu-timers: workaround to suppress the problems with mt exec (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=656264 (CONFIRM)
[oss-security] 20101123 CVE request: kernel: posix-cpu-timers: workaround to suppress the problems with mt exec (MLIST)
45028 (BID)
RHSA-2011:0004 (REDHAT)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e0a70217107e6f9844628120412cb27bb4cea194 (MISC)
CVE: CVE-2010-4243
CVE: CVE-2010-4243
Id:
CVE-2010-4243
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243
Comment
: fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101122 CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=625688 (CONFIRM)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
15619 (EXPLOIT-DB)
[linux-kernel] 20100827 [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[oss-security] 20101122 Re: CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
[linux-kernel] 20101130 [PATCH 1/2] exec: make argv/envp memory visible to oom-killer (MLIST)
http://grsecurity.net/~spender/64bit_dos.c (MISC)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
RHSA-2011:0017 (REDHAT)
42884 (SECUNIA)
45004 (BID)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
linux-kernel-execve-dos(64700) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c (MISC)
CVE: CVE-2010-4175
CVE: CVE-2010-4175
Id:
CVE-2010-4175
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4175
Comment
: Integer overflow in the rds_cmsg_rdma_args function (net/rds/rdma.c) in Linux kernel 2.6.35 allows local users to cause a denial of service (crash) and possibly trigger memory corruption via a crafted Reliable Datagram Sockets (RDS) request, a different vulnerability than CVE-2010-3865.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
[oss-security] 20101117 CVE request: kernel: integer overflow in RDS (MLIST)
[oss-security] 20101118 Re: CVE request: kernel: integer overflow in RDS (MLIST)
[linux-netdev] 20101117 [PATCH] Integer overflow in RDS cmsg handling (MLIST)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
42801 (SECUNIA)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
44921 (BID)
SUSE-SA:2011:004 (SUSE)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
kernel-rdscmsgrdmaargs-dos(64618) (XF)
CVE: CVE-2010-4169
CVE: CVE-2010-4169
Id:
CVE-2010-4169
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4169
Comment
: Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
416 (Use After Free)
References:
[oss-security] 20101115 CVE request: kernel: perf bug (MLIST)
44861 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
[oss-security] 20101115 Re: CVE request: kernel: perf bug (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=651671 (CONFIRM)
FEDORA-2010-18983 (FEDORA)
42745 (SECUNIA)
ADV-2010-3321 (VUPEN)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
kernel-perfeventmmap-dos(63316) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=63bfd7384b119409685a17d5c58f0b56e5dc03da (MISC)
CVE: CVE-2010-4165
CVE: CVE-2010-4165
Id:
CVE-2010-4165
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4165
Comment
: The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
369 (Divide By Zero)
References:
[netdev] 20101110 possible kernel oops from user MSS (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=652508 (CONFIRM)
69241 (OSVDB)
[oss-security] 20101112 CVE request: kernel: possible kernel oops from user MSS (MLIST)
[oss-security] 20101112 Re: CVE request: kernel: possible kernel oops from user MSS (MLIST)
[netdev] 20101110 Re: possible kernel oops from user MSS (MLIST)
SUSE-SA:2011:002 (SUSE)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
42801 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
44830 (BID)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
MDVSA-2011:051 (MANDRIVA)
8123 (SREASON)
8111 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7a1abd08d52fdeddb3e9a5a33f2f15cc6a5674d2 (MISC)
CVE: CVE-2010-4164
CVE: CVE-2010-4164
Id:
CVE-2010-4164
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4164
Comment
: Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3) X25_FAC_CLASS_C, or (4) X25_FAC_CLASS_D facility data, a different vulnerability than CVE-2010-3873.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
[oss-security] 20101112 Re: CVE request: kernel: remote DoS in X.25 (MLIST)
[netdev] 20101111 [SECURITY] [PATCH] Prevent crashing when parsing bad X.25 (MLIST)
[oss-security] 20101111 CVE request: kernel: remote DoS in X.25 (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=652517 (CONFIRM)
DSA-2126 (DEBIAN)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
SUSE-SA:2010:060 (SUSE)
45055 (BID)
42932 (SECUNIA)
ADV-2011-0124 (VUPEN)
SUSE-SA:2011:004 (SUSE)
43291 (SECUNIA)
ADV-2011-0298 (VUPEN)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:007 (SUSE)
SUSE-SA:2011:008 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5ef41308f94dcbb3b7afc56cdef1c2ba53fa5d2f (MISC)
CVE: CVE-2010-4668
CVE: CVE-2010-4668
Id:
CVE-2010-4668
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4668
Comment
: The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101130 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[linux-kernel] 20101129 [PATCH] block: check for proper length of iov entries earlier in blk_rq_map_user_iov() (MLIST)
https://patchwork.kernel.org/patch/363282/ (CONFIRM)
[oss-security] 20101130 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc7 (CONFIRM)
[linux-kernel] 20101129 Re: [PATCH] block: check for proper length of iov entries earlier in blk_rq_map_user_iov() (MLIST)
[oss-security] 20101129 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
45660 (BID)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
linux-blkrqmapuseriov-dos(64496) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5478755616ae2ef1ce144dded589b62b2a50d575 ()
CVE: CVE-2010-4163
CVE: CVE-2010-4163
Id:
CVE-2010-4163
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4163
Comment
: The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=652957 (CONFIRM)
[oss-security] 20101110 CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[oss-security] 20101112 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[oss-security] 20101129 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
SUSE-SA:2011:002 (SUSE)
SUSE-SA:2011:001 (SUSE)
44793 (BID)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9284bcf4e335e5f18a8bc7b26461c33ab60d0689 (MISC)
CVE: CVE-2010-4162
CVE: CVE-2010-4162
Id:
CVE-2010-4162
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4162
Comment
: Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20101110 CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=652529 (CONFIRM)
[oss-security] 20101112 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
42745 (SECUNIA)
FEDORA-2010-18983 (FEDORA)
ADV-2010-3321 (VUPEN)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
42778 (SECUNIA)
44793 (BID)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
SUSE-SA:2010:060 (SUSE)
42932 (SECUNIA)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb4644cac4a2797afc847e6c92736664d4b0ea34 (MISC)
CVE: CVE-2010-4158
CVE: CVE-2010-4158
Id:
CVE-2010-4158
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4158
Comment
: The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
20101118 Re: Kernel 0-day (BUGTRAQ)
20101109 Kernel 0-day (BUGTRAQ)
44758 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=651698 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
[netdev] 20101109 [PATCH] Prevent reading uninitialized memory with socket filters (MLIST)
20101109 Kernel 0-day (FULLDISC)
42745 (SECUNIA)
ADV-2010-3321 (VUPEN)
FEDORA-2010-18983 (FEDORA)
SUSE-SA:2011:002 (SUSE)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:001 (SUSE)
42801 (SECUNIA)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2010:060 (SUSE)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
RHSA-2011:0162 (REDHAT)
42963 (SECUNIA)
ADV-2011-0168 (VUPEN)
42884 (SECUNIA)
RHSA-2011:0007 (REDHAT)
RHSA-2011:0017 (REDHAT)
42890 (SECUNIA)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:008 (SUSE)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
43291 (SECUNIA)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=57fe93b374a6b8711995c2d466c502af9f3a08bb (MISC)
CVE: CVE-2010-3880
CVE: CVE-2010-3880
Id:
CVE-2010-3880
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3880
Comment
: net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20101104 CVE request: kernel: logic error in INET_DIAG bytecode auditing (MLIST)
[netdev] 20101103 [PATCH 2/2] inet_diag: Make sure we actually run the same bytecode we audited. (MLIST)
44665 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=651264 (CONFIRM)
[oss-security] 20101105 Re: CVE request: kernel: logic error in INET_DIAG bytecode auditing (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
42126 (SECUNIA)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0004 (REDHAT)
DSA-2126 (DEBIAN)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22e76c849d505d87c5ecf3d3e6742a65f0ff4860 (MISC)
CVE: CVE-2010-3877
CVE: CVE-2010-3877
Id:
CVE-2010-3877
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3877
Comment
: The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
[oss-security] 20101104 Re: CVE request: kernel stack infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=649717 (CONFIRM)
[netdev] 20101031 [PATCH 3/3] net: tipc: fix information leak to userland (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
[oss-security] 20101102 CVE request: kernel stack infoleaks (MLIST)
DSA-2126 (DEBIAN)
44630 (BID)
42884 (SECUNIA)
RHSA-2011:0017 (REDHAT)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-getname-info-disc(64578) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=88f8a5e3e7defccd3925cabb1ee4d3994e5cdb52 (MISC)
CVE: CVE-2010-3876
CVE: CVE-2010-3876
Id:
CVE-2010-3876
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3876
Comment
: net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
[oss-security] 20101104 Re: CVE request: kernel stack infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=649715 (CONFIRM)
[oss-security] 20101102 Re: CVE request: kernel stack infoleaks (MLIST)
[oss-security] 20101102 Re: CVE request: kernel stack infoleaks (MLIST)
[netdev] 20101031 [PATCH 2/3] net: packet: fix information leak to userland (MLIST)
[oss-security] 20101102 Re: CVE request: kernel stack infoleaks (MLIST)
[oss-security] 20101102 CVE request: kernel stack infoleaks (MLIST)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0004 (REDHAT)
DSA-2126 (DEBIAN)
ADV-2011-0024 (VUPEN)
44630 (BID)
42789 (SECUNIA)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67286640f638f5ad41a946b9a3dc75327950248f (MISC)
CVE: CVE-2010-3875
CVE: CVE-2010-3875
Id:
CVE-2010-3875
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3875
Comment
: The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=649713 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
[oss-security] 20101102 CVE request: kernel stack infoleaks (MLIST)
[netdev] 20101031 [PATCH 1/3] net: ax25: fix information leak to userland (MLIST)
[oss-security] 20101104 Re: CVE request: kernel stack infoleaks (MLIST)
DSA-2126 (DEBIAN)
44630 (BID)
MDVSA-2011:029 (MANDRIVA)
MDVSA-2011:051 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fe10ae53384e48c51996941b7720ee16995cbcb7 (MISC)
CVE: CVE-2010-3874
CVE: CVE-2010-3874
Id:
CVE-2010-3874
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3874
Comment
: Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
787 (Out-of-bounds Write)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=649695 (CONFIRM)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
[oss-security] 20101104 Re: CVE request: kernel: CAN information leak (MLIST)
[netdev] 20101110 can-bcm: fix minor heap overflow (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[oss-security] 20101103 CVE request: kernel: CAN information leak (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101102 [SECURITY] CAN info leak/minor heap overflow (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[oss-security] 20101220 CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
FEDORA-2010-18983 (FEDORA)
ADV-2010-3321 (VUPEN)
42745 (SECUNIA)
DSA-2126 (DEBIAN)
SUSE-SA:2011:001 (SUSE)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:002 (SUSE)
42801 (SECUNIA)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0597d1b99fcfc2c0eada09a698f85ed413d4ba84 (MISC)
CVE: CVE-2010-3859
CVE: CVE-2010-3859
Id:
CVE-2010-3859
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3859
Comment
: Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
[netdev] 20101027 Re: [PATCH 1/4] tipc: Fix bugs in tipc_msg_calc_data_size() (MLIST)
[netdev] 20101027 [PATCH 3/4] tipc: Update arguments to use size_t for iovec array sizes (MLIST)
[netdev] 20101027 [PATCH 1/4] tipc: Fix bugs in tipc_msg_calc_data_size() (MLIST)
[netdev] 20101027 [PATCH 2/4] tipc: Fix bugs in tipc_msg_build() (MLIST)
[netdev] 20101027 [PATCH 4/4] tipc: Fix bugs in sending of large amounts of byte-stream data (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=645867 (CONFIRM)
[oss-security] 20101022 CVE request: kernel: heap overflow in TIPC (MLIST)
[netdev] 20101028 Re: [PATCH 2/4] tipc: Fix bugs in tipc_msg_build() (MLIST)
[netdev] 20101027 [PATCH 0/4] RFC: tipc int vs size_t fixes (MLIST)
[oss-security] 20101022 Re: CVE request: kernel: heap overflow in TIPC (MLIST)
RHSA-2011:0004 (REDHAT)
DSA-2126 (DEBIAN)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
44354 (BID)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
[netdev] 20101021 TIPC security issues (MLIST)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=253eacc070b114c2ec1f81b067d2fed7305467b0 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8acfe468b0384e834a303f08ebc4953d72fb690a (MISC)
CVE: CVE-2011-4913
CVE: CVE-2011-4913
Id:
CVE-2011-4913
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4913
Comment
: The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/be20250c13f88375345ad99950190685eda51eb8 (CONFIRM)
[oss-security] 20111227 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=be20250c13f88375345ad99950190685eda51eb8 (MISC)
CVE: CVE-2011-3363
CVE: CVE-2011-3363
Id:
CVE-2011-3363
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3363
Comment
: The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
CVSSv2 Score:
6.1
Access vector:
ADJACENT_NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.5
Attack vector:
ADJACENT_NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110914 Re: CVE request -- kernel: cifs: always do is_path_accessible check in cifs_mount (MLIST)
https://github.com/torvalds/linux/commit/70945643722ffeac779d2529a348f99567fa5c33 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=738291 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=70945643722ffeac779d2529a348f99567fa5c33 (MISC)
CVE: CVE-2011-3359
CVE: CVE-2011-3359
Id:
CVE-2011-3359
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3359
Comment
: The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remote attackers to cause a denial of service (system crash) via a crafted frame.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://github.com/torvalds/linux/commit/c85ce65ecac078ab1a1835c87c4a6319cf74660a (CONFIRM)
[oss-security] 20110914 Re: CVE request -- kernel: b43: allocate receive buffers big enough for max frame len + offset (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=738202 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c85ce65ecac078ab1a1835c87c4a6319cf74660a (MISC)
CVE: CVE-2011-2498
CVE: CVE-2011-2498
Id:
CVE-2011-2498
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2498
Comment
: The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
http://marc.info/?l=oss-security&m=130923704824984&w=2 (MISC)
https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-2498.html (MISC)
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-1383-1 (MISC)
https://usn.ubuntu.com/1167-1/ (MISC)
https://security-tracker.debian.org/tracker/CVE-2011-2498 (MISC)
CVE: CVE-2011-2496
CVE: CVE-2011-2496
Id:
CVE-2011-2496
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496
Comment
: Integer overflow in the vma_to_resize function in mm/mremap.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (BUG_ON and system crash) via a crafted mremap system call that expands a memory mapping.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/982134ba62618c2d69fbbbd166d0a11ee3b7e3d8 (CONFIRM)
[oss-security] 20110627 Re: CVE request: kernel: mm: avoid wrapping vm_pgoff in mremap() and stack expansions (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=716538 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=982134ba62618c2d69fbbbd166d0a11ee3b7e3d8 (MISC)
CVE: CVE-2011-2479
CVE: CVE-2011-2479
Id:
CVE-2011-2479
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2479
Comment
: The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allows local users to cause a denial of service (system crash) via a crafted application.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
399 (Resource Management Errors)
References:
https://github.com/torvalds/linux/commit/78f11a255749d09025f54d4e2df4fbcb031530e2 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110620 Re: CVE request: kernel: thp: madvise on top of /dev/zero private mapping can lead to panic (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=714761 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78f11a255749d09025f54d4e2df4fbcb031530e2 (MISC)
CVE: CVE-2011-1776
CVE: CVE-2011-1776
Id:
CVE-2011-1776
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776
Comment
: The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (heap-based buffer overflow and OOPS) or obtain sensitive information from kernel heap memory by connecting a crafted GPT storage device, a different vulnerability than CVE-2011-1577.
CVSSv2 Score:
5.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:C
CVSSv3 Score:
6.1
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
47796 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=703026 (CONFIRM)
http://www.pre-cert.de/advisories/PRE-SA-2011-04.txt (MISC)
[oss-security] 20110510 Re: CVE request: kernel: validate size of EFI GUID partition entries (MLIST)
8369 (SREASON)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa039d5f6b126fbd65eefa05db2f67e44df8f121 (MISC)
CVE: CVE-2011-1771
CVE: CVE-2011-1771
Id:
CVE-2011-1771
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1771
Comment
: The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a file on a CIFS filesystem.
CVSSv2 Score:
4.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
476 (NULL Pointer Dereference)
References:
[linux-cifs] 20110405 Repeatable crash in 2.6.38 related to O_DIRECT (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=703016 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110509 CVE-2011-1771 kernel: cifs oops when creating file with O_DIRECT set (MLIST)
[linux-cifs] 20110405 Re: Repeatable crash in 2.6.38 related to O_DIRECT (MLIST)
8367 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7797069305d13252fd66cf722aa8f2cbeb3c95cd (MISC)
CVE: CVE-2011-1770
CVE: CVE-2011-1770
Id:
CVE-2011-1770
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770
Comment
: Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
FEDORA-2011-7551 (FEDORA)
https://bugzilla.redhat.com/show_bug.cgi?id=703011 (CONFIRM)
[linux-kernel] 20110506 Re: [PATCH] dccp: handle invalid feature options length (MLIST)
44932 (SECUNIA)
47769 (BID)
[linux-kernel] 20110506 [PATCH] dccp: handle invalid feature options length (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.33/ChangeLog-2.6.33.14 (CONFIRM)
1025592 (SECTRACK)
FEDORA-2011-7823 (FEDORA)
8286 (SREASON)
CVE: CVE-2011-1759
CVE: CVE-2011-1759
Id:
CVE-2011-1759
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1759
Comment
: Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory corruption) by providing a crafted argument and leveraging a race condition.
CVSSv2 Score:
6.2
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/0f22072ab50cac7983f9660d33974b45184da4f9 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110502 Re: CVE request: kernel (ARM): heap corruption in OABI semtimedop (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0f22072ab50cac7983f9660d33974b45184da4f9 (MISC)
CVE: CVE-2011-1746
CVE: CVE-2011-1746
Id:
CVE-2011-1746
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746
Comment
: Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specify a large number of memory pages.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698998 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110419 Re: [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
47535 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b522f02184b413955f3bc952e3776ce41edc6355 (MISC)
CVE: CVE-2011-2022
CVE: CVE-2011-2022
Id:
CVE-2011-2022
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2022
Comment
: The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
47843 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce ()
CVE: CVE-2011-1745
CVE: CVE-2011-1745
Id:
CVE-2011-1745
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745
Comment
: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
47534 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce (MISC)
CVE: CVE-2011-1748
CVE: CVE-2011-1748
Id:
CVE-2011-1748
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748
Comment
: The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[netdev] 20110420 [PATCH v2] can: add missing socket check in can/raw release (MLIST)
47835 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=10022a6c66e199d8f61d9044543f38785713cbbd (MISC)
CVE: CVE-2011-1598
CVE: CVE-2011-1598
Id:
CVE-2011-1598
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598
Comment
: The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[netdev] 20110420 Add missing socket check in can/bcm release. (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110420 CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110420 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
47503 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c6914a6f261aca0c9f715f883a353ae7ff51fe83 (MISC)
CVE: CVE-2011-1593
CVE: CVE-2011-1593
Id:
CVE-2011-1593
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593
Comment
: Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20110420 Re: CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
[linux-kernel] 20110418 Re: Kernel panic (NULL ptr deref?) in find_ge_pid()/next_pidmap() (via sys_getdents or sys_readdir) (MLIST)
44164 (SECUNIA)
https://bugzilla.redhat.com/show_bug.cgi?id=697822 (CONFIRM)
1025420 (SECTRACK)
[oss-security] 20110419 CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
47497 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.4 (CONFIRM)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-nextpidmap-dos(66876) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c78193e9c7bcbf25b8237ad0dec82f805c4ea69b (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d8bdc59f215e62098bc5b4256fd9928bf27053a1 (MISC)
CVE: CVE-2011-1495
CVE: CVE-2011-1495
Id:
CVE-2011-1495
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495
Comment
: drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1494
CVE: CVE-2011-1494
Id:
CVE-2011-1494
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494
Comment
: Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1479
CVE: CVE-2011-1479
Id:
CVE-2011-1479
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1479
Comment
: Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
[oss-security] 20110411 Re: CVE request: kernel: inotify memory leak (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=691793 (CONFIRM)
https://github.com/torvalds/linux/commit/d0de4dc584ec6aa3b26fffea320a8457827768fc (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d0de4dc584ec6aa3b26fffea320a8457827768fc (MISC)
CVE: CVE-2010-4250
CVE: CVE-2010-4250
Id:
CVE-2010-4250
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4250
Comment
: Memory leak in the inotify_init1 function in fs/notify/inotify/inotify_user.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory consumption) via vectors involving failed attempts to create files.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=656830 (CONFIRM)
[oss-security] 20101124 Re: CVE request: kernel: inotify memory leak (MLIST)
https://github.com/torvalds/linux/commit/a2ae4cc9a16e211c8a128ba10d22a85431f093ab (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a2ae4cc9a16e211c8a128ba10d22a85431f093ab (MISC)
CVE: CVE-2011-1477
CVE: CVE-2011-1477
Id:
CVE-2011-1477
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1477
Comment
: Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://github.com/torvalds/linux/commit/4d00135a680727f6c3be78f8befaac009030e4df (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4d00135a680727f6c3be78f8befaac009030e4df (MISC)
CVE: CVE-2011-1476
CVE: CVE-2011-1476
Id:
CVE-2011-1476
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1476
Comment
: Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/b769f49463711205d57286e64cf535ed4daf59e9 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b769f49463711205d57286e64cf535ed4daf59e9 (MISC)
CVE: CVE-2011-1180
CVE: CVE-2011-1180
Id:
CVE-2011-1180
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1180
Comment
: Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://github.com/torvalds/linux/commit/d370af0ef7951188daeb15bae75db7ba57c67846 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110322 Re: CVE requests - kernel: irda/decnet issues (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d370af0ef7951188daeb15bae75db7ba57c67846 ()
CVE: CVE-2011-1173
CVE: CVE-2011-1173
Id:
CVE-2011-1173
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173
Comment
: The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[netdev] 20110317 [PATCH] econet: 4 byte infoleak to the network (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14 (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8279 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67c5c6cb8129c595f21e88254a3fc6b3b841ae8e (MISC)
CVE: CVE-2011-2534
CVE: CVE-2011-2534
Id:
CVE-2011-2534
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2534
Comment
: Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[netfilter] 20110310 [PATCH] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689337 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[netfilter-devel] 20110317 [PATCH v2] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
46921 (BID)
8284 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=961ed183a9fd080cf306c659b8736007e44065a5 ()
CVE: CVE-2011-1172
CVE: CVE-2011-1172
Id:
CVE-2011-1172
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172
Comment
: net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv6: netfilter: ip6_tables: fix infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689345 (CONFIRM)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a8ab060779779de8aea92ce3337ca348f973f54 (MISC)
CVE: CVE-2011-1171
CVE: CVE-2011-1171
Id:
CVE-2011-1171
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171
Comment
: net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv4: netfilter: ip_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689327 (CONFIRM)
8278 (SREASON)
8283 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78b79876761b86653df89c48a7010b5cbd41a84a (MISC)
CVE: CVE-2011-1170
CVE: CVE-2011-1170
Id:
CVE-2011-1170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170
Comment
: net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[netfilter-devel] 20110310 [PATCH] ipv4: netfilter: arp_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689321 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8282 (SREASON)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=42eab94fff18cb1091d3501cd284d6bd6cc9c143 (MISC)
CVE: CVE-2011-1160
CVE: CVE-2011-1160
Id:
CVE-2011-1160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160
Comment
: The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/1309d7afbed112f0e8e90be9af975550caa0076b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=684671 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110315 Re: CVE requests - kernel: tpm infoleaks (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1309d7afbed112f0e8e90be9af975550caa0076b (MISC)
CVE: CVE-2011-1093
CVE: CVE-2011-1093
Id:
CVE-2011-1093
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093
Comment
: The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
46793 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=682954 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[oss-security] 20110308 CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
[oss-security] 20110308 Re: CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=720dc34bbbe9493c7bd48b2243058b4e447a929d (MISC)
CVE: CVE-2011-1080
CVE: CVE-2011-1080
Id:
CVE-2011-1080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080
Comment
: The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=681262 (CONFIRM)
https://github.com/torvalds/linux/commit/d846f71195d57b0bbb143382647c2c6638b04c5a (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d846f71195d57b0bbb143382647c2c6638b04c5a (MISC)
CVE: CVE-2011-1079
CVE: CVE-2011-1079
Id:
CVE-2011-1079
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079
Comment
: The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://github.com/torvalds/linux/commit/43629f8f5ea32a998d06d1bb41eefa0e821ff573 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681260 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.html (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=43629f8f5ea32a998d06d1bb41eefa0e821ff573 (MISC)
CVE: CVE-2011-1078
CVE: CVE-2011-1078
Id:
CVE-2011-1078
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078
Comment
: The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681259 (CONFIRM)
https://github.com/torvalds/linux/commit/c4c896e1471aec3b004a693c689f60be3b17ac86 (CONFIRM)
RHSA-2012:1156 (REDHAT)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c4c896e1471aec3b004a693c689f60be3b17ac86 (MISC)
CVE: CVE-2011-1017
CVE: CVE-2011-1017
Id:
CVE-2011-1017
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1017
Comment
: Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
[oss-security] 20110224 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
[oss-security] 20110223 CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
1025128 (SECTRACK)
[oss-security] 20110223 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
43738 (SECUNIA)
43716 (SECUNIA)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
CVE: CVE-2011-0463
CVE: CVE-2011-0463
Id:
CVE-2011-0463
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0463
Comment
: The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc1 (CONFIRM)
[ocfs2-devel] 20110217 [PATCH] Treat writes as new when holes span across page boundaries (MLIST)
43966 (SECUNIA)
https://bugzilla.novell.com/show_bug.cgi?id=673037 (CONFIRM)
USN-1146-1 (UBUNTU)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=272b62c1f0f6f742046e45b50b6fec98860208a0 ()
CVE: CVE-2011-1927
CVE: CVE-2011-1927
Id:
CVE-2011-1927
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1927
Comment
: The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE:
CWE-Other ()
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://github.com/torvalds/linux/commit/64f3b9e203bd06855072e295557dca1485a2ecba (CONFIRM)
[oss-security] 20110518 Re: CVE request: kernel: net: ip_expire() must revalidate route (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=64f3b9e203bd06855072e295557dca1485a2ecba (MISC)
Content available only for registered users!
ovaldb@altx-soft.com