Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:ru.altx-soft.nix:def:15398
[Eng]
Version
12
Class
patch
ALTXid
27516
Language
Russian
Severity
Critical
Title
Обновление USN-1202-1 -- уязвимости Linux kernel (OMAP4)
Description
linux-ti-omap4: Linux kernel for OMAP4 Multiple kernel flaws have been fixed.
Family
unix
Platform
Ubuntu 10.10
Product
Linux
Reference
VENDOR: USN-1202-1
VENDOR: USN-1202-1
Id:
USN-1202-1
Reference:
https://usn.ubuntu.com/usn/usn-1202-1
CVE: CVE-2011-4914
CVE: CVE-2011-4914
Id:
CVE-2011-4914
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4914
Comment
: The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.
CVSSv2 Score:
6.4
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20111227 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/e0bccd315db0c2f919e7fcf9cb60db21d9986f52 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e0bccd315db0c2f919e7fcf9cb60db21d9986f52 (MISC)
CVE: CVE-2011-4913
CVE: CVE-2011-4913
Id:
CVE-2011-4913
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4913
Comment
: The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/be20250c13f88375345ad99950190685eda51eb8 (CONFIRM)
[oss-security] 20111227 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=be20250c13f88375345ad99950190685eda51eb8 (MISC)
CVE: CVE-2011-3637
CVE: CVE-2011-3637
Id:
CVE-2011-3637
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3637
Comment
: The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=747848 (CONFIRM)
[oss-security] 20120206 CVE-2011-3637 Linux kernel: proc: fix Oops on invalid /proc/
/maps access (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://github.com/torvalds/linux/commit/76597cd31470fa130784c78fadb4dab2e624a723 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=76597cd31470fa130784c78fadb4dab2e624a723 (MISC)
CVE: CVE-2011-2918
CVE: CVE-2011-2918
Id:
CVE-2011-2918
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2918
Comment
: The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
https://github.com/torvalds/linux/commit/a8b0ca17b80e92faab46ee7179ba9e99ccb61233 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1 (CONFIRM)
[oss-security] 20110816 Re: CVE request -- kernel: perf: fix software event overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=730706 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a8b0ca17b80e92faab46ee7179ba9e99ccb61233 (MISC)
CVE: CVE-2011-2699
CVE: CVE-2011-2699
Id:
CVE-2011-2699
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699
Comment
: The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=723429 (CONFIRM)
[oss-security] 20110720 Re: CVE request: kernel: ipv6: make fragment identifications less predictable (MLIST)
https://github.com/torvalds/linux/commit/87c48fa3b4630905f98268dde838ee43626a060c (CONFIRM)
1027274 (SECTRACK)
MDVSA-2013:150 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=87c48fa3b4630905f98268dde838ee43626a060c (MISC)
CVE: CVE-2011-2492
CVE: CVE-2011-2492
Id:
CVE-2011-2492
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492
Comment
: The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110624 CVE request: kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace (MLIST)
[linux-bluetooth] 20110508 Bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace. (MLIST)
1025778 (SECTRACK)
[oss-security] 20110624 Re: CVE request: kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v3.0/testing/ChangeLog-3.0-rc4 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=703019 (CONFIRM)
RHSA-2011:0927 (REDHAT)
HPSBGN02970 (HP)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8d03e971cf403305217b8e62db3a2e5ad2d6263f (MISC)
CVE: CVE-2011-2484
CVE: CVE-2011-2484
Id:
CVE-2011-2484
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484
Comment
: The add_del_listener function in kernel/taskstats.c in the Linux kernel 2.6.39.1 and earlier does not prevent multiple registrations of exit handlers, which allows local users to cause a denial of service (memory and CPU consumption), and bypass the OOM Killer, via a crafted application.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
[linux-kernel] 20110616 [PATCH] taskstats: don't allow duplicate entries in listener mode (MLIST)
[oss-security] 20110622 Re: CVE request: kernel: taskstats local DoS (MLIST)
[oss-security] 20110622 CVE request: kernel: taskstats local DoS (MLIST)
48383 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=715436 (MISC)
kernel-taskstats-dos(68150) (XF)
CVE: CVE-2011-1833
CVE: CVE-2011-1833
Id:
CVE-2011-1833
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833
Comment
: Race condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the eCryptfs subsystem in the Linux kernel before 3.1 allows local users to bypass intended file permissions via a mount.ecryptfs_private mount with a mismatched uid.
CVSSv2 Score:
3.3
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:N
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=731172 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1 (CONFIRM)
https://github.com/torvalds/linux/commit/764355487ea220fdc2faf128d577d7f679b91f97 (CONFIRM)
USN-1188-1 (UBUNTU)
SUSE-SU-2011:0898 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=764355487ea220fdc2faf128d577d7f679b91f97 ()
CVE: CVE-2011-1770
CVE: CVE-2011-1770
Id:
CVE-2011-1770
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770
Comment
: Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
FEDORA-2011-7551 (FEDORA)
https://bugzilla.redhat.com/show_bug.cgi?id=703011 (CONFIRM)
[linux-kernel] 20110506 Re: [PATCH] dccp: handle invalid feature options length (MLIST)
44932 (SECUNIA)
47769 (BID)
[linux-kernel] 20110506 [PATCH] dccp: handle invalid feature options length (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.33/ChangeLog-2.6.33.14 (CONFIRM)
1025592 (SECTRACK)
FEDORA-2011-7823 (FEDORA)
8286 (SREASON)
CVE: CVE-2011-1746
CVE: CVE-2011-1746
Id:
CVE-2011-1746
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746
Comment
: Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specify a large number of memory pages.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698998 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110419 Re: [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
47535 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b522f02184b413955f3bc952e3776ce41edc6355 (MISC)
CVE: CVE-2011-2022
CVE: CVE-2011-2022
Id:
CVE-2011-2022
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2022
Comment
: The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
47843 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce ()
CVE: CVE-2011-1745
CVE: CVE-2011-1745
Id:
CVE-2011-1745
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745
Comment
: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
47534 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce (MISC)
CVE: CVE-2011-1748
CVE: CVE-2011-1748
Id:
CVE-2011-1748
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748
Comment
: The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[netdev] 20110420 [PATCH v2] can: add missing socket check in can/raw release (MLIST)
47835 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=10022a6c66e199d8f61d9044543f38785713cbbd (MISC)
CVE: CVE-2011-1598
CVE: CVE-2011-1598
Id:
CVE-2011-1598
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598
Comment
: The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[netdev] 20110420 Add missing socket check in can/bcm release. (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110420 CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110420 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
47503 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c6914a6f261aca0c9f715f883a353ae7ff51fe83 (MISC)
CVE: CVE-2011-1593
CVE: CVE-2011-1593
Id:
CVE-2011-1593
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593
Comment
: Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20110420 Re: CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
[linux-kernel] 20110418 Re: Kernel panic (NULL ptr deref?) in find_ge_pid()/next_pidmap() (via sys_getdents or sys_readdir) (MLIST)
44164 (SECUNIA)
https://bugzilla.redhat.com/show_bug.cgi?id=697822 (CONFIRM)
1025420 (SECTRACK)
[oss-security] 20110419 CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
47497 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.4 (CONFIRM)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-nextpidmap-dos(66876) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c78193e9c7bcbf25b8237ad0dec82f805c4ea69b (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d8bdc59f215e62098bc5b4256fd9928bf27053a1 (MISC)
CVE: CVE-2011-1577
CVE: CVE-2011-1577
Id:
CVE-2011-1577
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577
Comment
: Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-table header on removable media.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
47343 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=695976 (CONFIRM)
[oss-security] 20110413 Re: CVE Request: kernel: fs/partitions: Corrupted GUID partition tables can cause kernel oops (MLIST)
[mm-commits] 20110412 + fs-partitions-efic-corrupted-guid-partition-tables-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110412 CVE Request: kernel: fs/partitions: Corrupted GUID partition tables can cause kernel oops (MLIST)
1025355 (SECTRACK)
FEDORA-2011-7823 (FEDORA)
8238 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
kernel-guid-dos(66773) (XF)
20110413 [PRE-SA-2011-03] Denial-of-service vulnerability in EFI partition handling code of the Linux kernel (BUGTRAQ)
CVE: CVE-2011-1495
CVE: CVE-2011-1495
Id:
CVE-2011-1495
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495
Comment
: drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1494
CVE: CVE-2011-1494
Id:
CVE-2011-1494
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494
Comment
: Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1493
CVE: CVE-2011-1493
Id:
CVE-2011-1493
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493
Comment
: Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DIGIS data that specifies a large number of digipeaters, and then sending this data to a ROSE socket.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE:
CWE-Other ()
References:
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/be20250c13f88375345ad99950190685eda51eb8 (CONFIRM)
[oss-security] 20110405 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=be20250c13f88375345ad99950190685eda51eb8 (MISC)
CVE: CVE-2011-1478
CVE: CVE-2011-1478
Id:
CVE-2011-1478
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478
Comment
: The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=691270 (CONFIRM)
46397 (SECUNIA)
[oss-security] 20110328 CVE-2011-1478 kernel: gro: reset dev and skb_iff on skb reuse (MLIST)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
8480 (SREASON)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6d152e23ad1a7a5b40fef1f42e017d66e6115159 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=66c46d741e2e60f0e8b625b80edb0ab820c46d7a (MISC)
CVE: CVE-2011-1182
CVE: CVE-2011-1182
Id:
CVE-2011-1182
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182
Comment
: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=690028 (CONFIRM)
https://github.com/torvalds/linux/commit/da48524eb20662618854bb3df2db01fc65f3070c (CONFIRM)
[oss-security] 20110323 Re: Linux kernel signal spoofing vulnerability (CVE request) (MLIST)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=da48524eb20662618854bb3df2db01fc65f3070c (MISC)
CVE: CVE-2011-1180
CVE: CVE-2011-1180
Id:
CVE-2011-1180
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1180
Comment
: Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://github.com/torvalds/linux/commit/d370af0ef7951188daeb15bae75db7ba57c67846 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110322 Re: CVE requests - kernel: irda/decnet issues (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d370af0ef7951188daeb15bae75db7ba57c67846 ()
CVE: CVE-2011-1173
CVE: CVE-2011-1173
Id:
CVE-2011-1173
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173
Comment
: The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[netdev] 20110317 [PATCH] econet: 4 byte infoleak to the network (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14 (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8279 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67c5c6cb8129c595f21e88254a3fc6b3b841ae8e (MISC)
CVE: CVE-2011-2534
CVE: CVE-2011-2534
Id:
CVE-2011-2534
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2534
Comment
: Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[netfilter] 20110310 [PATCH] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689337 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[netfilter-devel] 20110317 [PATCH v2] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
46921 (BID)
8284 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=961ed183a9fd080cf306c659b8736007e44065a5 ()
CVE: CVE-2011-1172
CVE: CVE-2011-1172
Id:
CVE-2011-1172
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172
Comment
: net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv6: netfilter: ip6_tables: fix infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689345 (CONFIRM)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a8ab060779779de8aea92ce3337ca348f973f54 (MISC)
CVE: CVE-2011-1171
CVE: CVE-2011-1171
Id:
CVE-2011-1171
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171
Comment
: net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv4: netfilter: ip_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689327 (CONFIRM)
8278 (SREASON)
8283 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78b79876761b86653df89c48a7010b5cbd41a84a (MISC)
CVE: CVE-2011-1170
CVE: CVE-2011-1170
Id:
CVE-2011-1170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170
Comment
: net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[netfilter-devel] 20110310 [PATCH] ipv4: netfilter: arp_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689321 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8282 (SREASON)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=42eab94fff18cb1091d3501cd284d6bd6cc9c143 (MISC)
CVE: CVE-2011-1169
CVE: CVE-2011-1169
Id:
CVE-2011-1169
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1169
Comment
: Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
129 (Improper Validation of Array Index)
References:
[oss-security] 20110318 Re: CVE request: kernel: AudioScience HPI driver (MLIST)
[oss-security] 20110318 CVE request: kernel: AudioScience HPI driver (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=688898 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.1 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=4a122c10fbfe9020df469f0f669da129c5757671 (MISC)
CVE: CVE-2011-1163
CVE: CVE-2011-1163
Id:
CVE-2011-1163
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163
Comment
: The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=688021 (CONFIRM)
1025225 (SECTRACK)
[oss-security] 20110315 Re: CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
[oss-security] 20110315 CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-02.txt (MISC)
[mm-commits] 20110314 + fs-partitions-osfc-corrupted-osf-partition-table-can-cause-information-disclosure.patch added to -mm tree (MLIST)
20110317 [PRE-SA-2011-02] Information disclosure vulnerability in the OSF partition handling code of the Linux kernel (BUGTRAQ)
46878 (BID)
8189 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1eafbfeb7bdf59cfe173304c76188f3fd5f1fd05 (MISC)
CVE: CVE-2011-1160
CVE: CVE-2011-1160
Id:
CVE-2011-1160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160
Comment
: The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/1309d7afbed112f0e8e90be9af975550caa0076b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=684671 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110315 Re: CVE requests - kernel: tpm infoleaks (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1309d7afbed112f0e8e90be9af975550caa0076b (MISC)
CVE: CVE-2011-1093
CVE: CVE-2011-1093
Id:
CVE-2011-1093
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093
Comment
: The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
46793 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=682954 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[oss-security] 20110308 CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
[oss-security] 20110308 Re: CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=720dc34bbbe9493c7bd48b2243058b4e447a929d (MISC)
CVE: CVE-2011-1090
CVE: CVE-2011-1090
Id:
CVE-2011-1090
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090
Comment
: The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=682641 (CONFIRM)
[oss-security] 20110307 Re: CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
1025336 (SECTRACK)
[oss-security] 20110307 CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9e3d724e2145f5039b423c290ce2b2c3d8f94bc (MISC)
CVE: CVE-2011-1082
CVE: CVE-2011-1082
Id:
CVE-2011-1082
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082
Comment
: fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20110301 CVE request: kernel: Multiple DoS issues in epoll (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681575 (CONFIRM)
[oss-security] 20110302 Re: CVE request: kernel: Multiple DoS issues in epoll (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[linux-kernel] 20110205 [PATCH] epoll: Prevent deadlock through unsafe ->f_op->poll() calls. (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e (MISC)
CVE: CVE-2011-1080
CVE: CVE-2011-1080
Id:
CVE-2011-1080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080
Comment
: The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=681262 (CONFIRM)
https://github.com/torvalds/linux/commit/d846f71195d57b0bbb143382647c2c6638b04c5a (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d846f71195d57b0bbb143382647c2c6638b04c5a (MISC)
CVE: CVE-2011-1079
CVE: CVE-2011-1079
Id:
CVE-2011-1079
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079
Comment
: The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://github.com/torvalds/linux/commit/43629f8f5ea32a998d06d1bb41eefa0e821ff573 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681260 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.html (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=43629f8f5ea32a998d06d1bb41eefa0e821ff573 (MISC)
CVE: CVE-2011-1078
CVE: CVE-2011-1078
Id:
CVE-2011-1078
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078
Comment
: The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681259 (CONFIRM)
https://github.com/torvalds/linux/commit/c4c896e1471aec3b004a693c689f60be3b17ac86 (CONFIRM)
RHSA-2012:1156 (REDHAT)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c4c896e1471aec3b004a693c689f60be3b17ac86 (MISC)
CVE: CVE-2011-1020
CVE: CVE-2011-1020
Id:
CVE-2011-1020
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020
Comment
: The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE:
200 (Information Exposure)
References:
[oss-security] 20110225 Re: CVE request: kernel: /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
43496 (SECUNIA)
[oss-security] 20110224 CVE request: kernel: /proc/$pid/ leaks contents across setuid exec (MLIST)
20110122 Proc filesystem and SUID-Binaries (FULLDISC)
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
http://www.halfdog.net/Security/2011/SuidBinariesAndProcInterface/ (MISC)
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
46567 (BID)
8107 (SREASON)
kernel-procpid-security-bypass(65693) (XF)
CVE: CVE-2011-1019
CVE: CVE-2011-1019
Id:
CVE-2011-1019
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019
Comment
: The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
References:
https://github.com/torvalds/linux/commit/8909c9ad8ff03611c9c96c9a92656213e4bb495b (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: CAP_SYS_MODULE bypass via CAP_NET_ADMIN (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680360 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8909c9ad8ff03611c9c96c9a92656213e4bb495b (MISC)
CVE: CVE-2011-1017
CVE: CVE-2011-1017
Id:
CVE-2011-1017
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1017
Comment
: Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
[oss-security] 20110224 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
[oss-security] 20110223 CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
1025128 (SECTRACK)
[oss-security] 20110223 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
43738 (SECUNIA)
43716 (SECUNIA)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
CVE: CVE-2011-1016
CVE: CVE-2011-1016
Id:
CVE-2011-1016
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016
Comment
: The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
46557 (BID)
[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680000 (CONFIRM)
kernel-atiradeon-sec-bypass(65691) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef (MISC)
CVE: CVE-2011-1013
CVE: CVE-2011-1013
Id:
CVE-2011-1013
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013
Comment
: Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via a crafted num_crtcs (aka vb_num) structure member in an ioctl argument.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c (CONFIRM)
47639 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=679925 (CONFIRM)
kernel-drmioctl-priv-escalation(67199) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1922756124ddd53846877416d92ba4a802bc658f (MISC)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c.diff?r1=1.41%3Br2=1.42%3Bf=h (MISC)
CVE: CVE-2011-1012
CVE: CVE-2011-1012
Id:
CVE-2011-1012
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1012
Comment
: The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
369 (Divide By Zero)
References:
[mm-commits] 20110222 + ldm-corrupted-partition-table-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110223 CVE request: kernel: Corrupted LDM partition table issues (MLIST)
[oss-security] 20110223 Re: CVE request: kernel: Corrupted LDM partition table issues (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git6.log (CONFIRM)
1025127 (SECTRACK)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=294f6cf48666825d23c9372ef37631232746e40d (MISC)
CVE: CVE-2011-1010
CVE: CVE-2011-1010
Id:
CVE-2011-1010
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010
Comment
: Buffer overflow in the mac_partition function in fs/partitions/mac.c in the Linux kernel before 2.6.37.2 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via a malformed Mac OS partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=679282 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37.2 (CONFIRM)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
[oss-security] 20110222 CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
1025126 (SECTRACK)
46492 (BID)
8115 (SREASON)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-map-dos(65643) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa7ea87a057958a8b7926c1a60a3ca6d696328ed (MISC)
CVE: CVE-2011-0726
CVE: CVE-2011-0726
Id:
CVE-2011-0726
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726
Comment
: The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110311 [PATCH] proc: protect mm start_code/end_code in /proc/pid/stat (MLIST)
[mm-commits] 20110314 + proc-protect-mm-start_code-end_code-in-proc-pid-stat.patch added to -mm tree (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=684569 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.39/ChangeLog-2.6.39-rc1 (CONFIRM)
47791 (BID)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5883f57ca0008ffc93e09cbb9847a1928e50c6f3 ()
CVE: CVE-2011-0712
CVE: CVE-2011-0712
Id:
CVE-2011-0712
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712
Comment
: Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20110216 kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.38-rc4-next-20110215.bz2 (CONFIRM)
46419 (BID)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=677881 (CONFIRM)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
USN-1146-1 (UBUNTU)
kernel-usbdevice-bo(65461) (XF)
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=eaae55dac6b64c0616046436b294e69fc5311581 (MISC)
CVE: CVE-2011-0711
CVE: CVE-2011-0711
Id:
CVE-2011-0711
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711
Comment
: The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=677260 (CONFIRM)
46417 (BID)
[oss-security] 20110216 Re: CVE request - kernel: xfs infoleak (MLIST)
[oss-security] 20110216 CVE request - kernel: xfs infoleak (MLIST)
https://patchwork.kernel.org/patch/555461/ (CONFIRM)
70950 (OSVDB)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git3.log (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3a3675b7f23f83ca8c67c9c2b6edf707fd28d1ba (MISC)
CVE: CVE-2011-0695
CVE: CVE-2011-0695
Id:
CVE-2011-0695
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695
Comment
: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[linux-rdma] 20110223 [PATCH 2/2] ib/cm: Bump reference count on cm_id before invoking callback (MLIST)
43693 (SECUNIA)
46839 (BID)
[linux-rdma] 20110223 [PATCH 1/2] rdma/cm: Fix crash in request handlers (MLIST)
[oss-security] 20110311 CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler (MLIST)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-infiniband-dos(66056) (XF)
CVE: CVE-2011-0521
CVE: CVE-2011-0521
Id:
CVE-2011-0521
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521
Comment
: The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc2 (CONFIRM)
[oss-security] 20110125 Re: Linux kernel av7110 negative array offset (MLIST)
43009 (SECUNIA)
[oss-security] 20110125 Linux kernel av7110 negative array offset (MLIST)
45986 (BID)
1025195 (SECTRACK)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-av7110ca-privilege-escalation(64988) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb26a24ee9706473f31d34cc259f4dcf45cd0644 (MISC)
CVE: CVE-2011-0463
CVE: CVE-2011-0463
Id:
CVE-2011-0463
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0463
Comment
: The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc1 (CONFIRM)
[ocfs2-devel] 20110217 [PATCH] Treat writes as new when holes span across page boundaries (MLIST)
43966 (SECUNIA)
https://bugzilla.novell.com/show_bug.cgi?id=673037 (CONFIRM)
USN-1146-1 (UBUNTU)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=272b62c1f0f6f742046e45b50b6fec98860208a0 ()
CVE: CVE-2010-4656
CVE: CVE-2010-4656
Id:
CVE-2010-4656
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4656
Comment
: The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
[oss-security] 20110125 Re: CVE request: linux kernel heap issues (MLIST)
[oss-security] 20110124 Re: CVE request: linux kernel heap issues (MLIST)
46069 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=672420 (CONFIRM)
[oss-security] 20110124 CVE request: linux kernel heap issues (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
USN-1146-1 (UBUNTU)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3ed780117dbe5acb64280d218f0347f238dafed0 (MISC)
CVE: CVE-2010-4655
CVE: CVE-2010-4655
Id:
CVE-2010-4655
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4655
Comment
: net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
665 (Improper Initialization)
References:
[oss-security] 20110124 CVE request: linux kernel heap issues (MLIST)
[linux-kernel] 20101007 [PATCH] net: clear heap allocations for privileged ethtool actions (MLIST)
[oss-security] 20110125 Re: CVE request: linux kernel heap issues (MLIST)
[oss-security] 20110124 Re: CVE request: linux kernel heap issues (MLIST)
[oss-security] 20110125 Re: CVE request: linux kernel heap issues (MLIST)
45972 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=672428 (CONFIRM)
[oss-security] 20110128 Re: CVE request: linux kernel heap issues (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
USN-1146-1 (UBUNTU)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b00916b189d13a615ff05c9242201135992fcda3 (MISC)
CVE: CVE-2011-1044
CVE: CVE-2011-1044
Id:
CVE-2011-1044
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1044
Comment
: The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=667916 (CONFIRM)
46488 (BID)
RHSA-2011:0927 (REDHAT)
kernel-ibuverbspollcq-info-disclosure(65563) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7182afea8d1afd432a17c18162cc3fd441d0da93 ()
CVE: CVE-2010-4649
CVE: CVE-2010-4649
Id:
CVE-2010-4649
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649
Comment
: Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
46073 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=667916 (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7182afea8d1afd432a17c18162cc3fd441d0da93 (MISC)
CVE: CVE-2010-4565
CVE: CVE-2010-4565
Id:
CVE-2010-4565
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565
Comment
: The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101220 CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101110 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101109 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101102 [SECURITY] CAN info leak/minor heap overflow (MLIST)
[oss-security] 20101104 Re: CVE request: kernel: CAN information leak (MLIST)
[oss-security] 20101103 CVE request: kernel: CAN information leak (MLIST)
44661 (BID)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101102 Re: [SECURITY] CAN info leak/minor heap overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=664544 (MISC)
MDVSA-2011:029 (MANDRIVA)
CVE: CVE-2010-4256
CVE: CVE-2010-4256
Id:
CVE-2010-4256
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4256
Comment
: The pipe_fcntl function in fs/pipe.c in the Linux kernel before 2.6.37 does not properly determine whether a file is a named pipe, which allows local users to cause a denial of service via an F_SETPIPE_SZ fcntl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20101130 Re: CVE request: kernel: pipe_fcntl local DoS (MLIST)
[oss-security] 20101130 CVE request: kernel: pipe_fcntl local DoS (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c66fb347946ebdd5b10908866ecc9fa05ee2cf3d (MISC)
CVE: CVE-2010-4248
CVE: CVE-2010-4248
Id:
CVE-2010-4248
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4248
Comment
: Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[oss-security] 20101124 Re: CVE request: kernel: posix-cpu-timers: workaround to suppress the problems with mt exec (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=656264 (CONFIRM)
[oss-security] 20101123 CVE request: kernel: posix-cpu-timers: workaround to suppress the problems with mt exec (MLIST)
45028 (BID)
RHSA-2011:0004 (REDHAT)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e0a70217107e6f9844628120412cb27bb4cea194 (MISC)
CVE: CVE-2010-4243
CVE: CVE-2010-4243
Id:
CVE-2010-4243
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243
Comment
: fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101122 CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=625688 (CONFIRM)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
15619 (EXPLOIT-DB)
[linux-kernel] 20100827 [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[oss-security] 20101122 Re: CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
[linux-kernel] 20101130 [PATCH 1/2] exec: make argv/envp memory visible to oom-killer (MLIST)
http://grsecurity.net/~spender/64bit_dos.c (MISC)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
RHSA-2011:0017 (REDHAT)
42884 (SECUNIA)
45004 (BID)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
linux-kernel-execve-dos(64700) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c (MISC)
CVE: CVE-2010-4242
CVE: CVE-2010-4242
Id:
CVE-2010-4242
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4242
Comment
: The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL pointer dereference) via vectors related to the Bluetooth driver.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
CWE-Other ()
References:
http://xorl.wordpress.com/2010/12/01/cve-2010-4242-linux-kernel-bluetooth-hci-uart-invalid-pointer-access/ (MISC)
http://git.kernel.org/linus/c19483cc5e56ac5e22dd19cf25ba210ab1537773 (CONFIRM)
[linux-kernel] 20101007 Peculiar stuff in hci_ath3k/badness in hci_uart (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=641410 (CONFIRM)
RHSA-2011:0004 (REDHAT)
45014 (BID)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
43291 (SECUNIA)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:008 (SUSE)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-hciuartttyopen-dos(64617) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2010-4175
CVE: CVE-2010-4175
Id:
CVE-2010-4175
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4175
Comment
: Integer overflow in the rds_cmsg_rdma_args function (net/rds/rdma.c) in Linux kernel 2.6.35 allows local users to cause a denial of service (crash) and possibly trigger memory corruption via a crafted Reliable Datagram Sockets (RDS) request, a different vulnerability than CVE-2010-3865.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
[oss-security] 20101117 CVE request: kernel: integer overflow in RDS (MLIST)
[oss-security] 20101118 Re: CVE request: kernel: integer overflow in RDS (MLIST)
[linux-netdev] 20101117 [PATCH] Integer overflow in RDS cmsg handling (MLIST)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
42801 (SECUNIA)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
44921 (BID)
SUSE-SA:2011:004 (SUSE)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
kernel-rdscmsgrdmaargs-dos(64618) (XF)
CVE: CVE-2010-4169
CVE: CVE-2010-4169
Id:
CVE-2010-4169
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4169
Comment
: Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
416 (Use After Free)
References:
[oss-security] 20101115 CVE request: kernel: perf bug (MLIST)
44861 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
[oss-security] 20101115 Re: CVE request: kernel: perf bug (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=651671 (CONFIRM)
FEDORA-2010-18983 (FEDORA)
42745 (SECUNIA)
ADV-2010-3321 (VUPEN)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
kernel-perfeventmmap-dos(63316) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=63bfd7384b119409685a17d5c58f0b56e5dc03da (MISC)
CVE: CVE-2010-4668
CVE: CVE-2010-4668
Id:
CVE-2010-4668
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4668
Comment
: The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101130 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[linux-kernel] 20101129 [PATCH] block: check for proper length of iov entries earlier in blk_rq_map_user_iov() (MLIST)
https://patchwork.kernel.org/patch/363282/ (CONFIRM)
[oss-security] 20101130 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc7 (CONFIRM)
[linux-kernel] 20101129 Re: [PATCH] block: check for proper length of iov entries earlier in blk_rq_map_user_iov() (MLIST)
[oss-security] 20101129 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
45660 (BID)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
linux-blkrqmapuseriov-dos(64496) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5478755616ae2ef1ce144dded589b62b2a50d575 ()
CVE: CVE-2010-4163
CVE: CVE-2010-4163
Id:
CVE-2010-4163
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4163
Comment
: The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=652957 (CONFIRM)
[oss-security] 20101110 CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[oss-security] 20101112 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
[oss-security] 20101129 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
SUSE-SA:2011:002 (SUSE)
SUSE-SA:2011:001 (SUSE)
44793 (BID)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9284bcf4e335e5f18a8bc7b26461c33ab60d0689 (MISC)
CVE: CVE-2010-4162
CVE: CVE-2010-4162
Id:
CVE-2010-4162
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4162
Comment
: Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20101110 CVE request: kernel: Multiple DoS issues in block layer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=652529 (CONFIRM)
[oss-security] 20101112 Re: CVE request: kernel: Multiple DoS issues in block layer (MLIST)
42745 (SECUNIA)
FEDORA-2010-18983 (FEDORA)
ADV-2010-3321 (VUPEN)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
42778 (SECUNIA)
44793 (BID)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
SUSE-SA:2010:060 (SUSE)
42932 (SECUNIA)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb4644cac4a2797afc847e6c92736664d4b0ea34 (MISC)
CVE: CVE-2010-4160
CVE: CVE-2010-4160
Id:
CVE-2010-4160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4160
Comment
: Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20101124 Re: CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
[oss-security] 20101124 Re: CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
[oss-security] 20101124 Re: CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
[oss-security] 20101110 CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
[netdev] 20101031 [SECURITY] L2TP send buffer allocation size overflows (MLIST)
[oss-security] 20101110 Re: CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=651892 (CONFIRM)
[oss-security] 20101124 Re: CVE request: kernel: L2TP send buffer allocation size overflows (MLIST)
[netdev] 20101027 Re: [PATCH 1/4] tipc: Fix bugs in tipc_msg_calc_data_size() (MLIST)
SUSE-SA:2011:002 (SUSE)
http://xorl.wordpress.com/2010/11/11/cve-2010-4160-linux-kernel-l2tp-integer-overflows/ (MISC)
ADV-2011-0012 (VUPEN)
44762 (BID)
42801 (SECUNIA)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0213 (VUPEN)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
SUSE-SA:2011:005 (SUSE)
43056 (SECUNIA)
ADV-2011-0375 (VUPEN)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=253eacc070b114c2ec1f81b067d2fed7305467b0 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8acfe468b0384e834a303f08ebc4953d72fb690a (MISC)
CVE: CVE-2010-4157
CVE: CVE-2010-4157
Id:
CVE-2010-4157
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4157
Comment
: Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
CVSSv2 Score:
6.2
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[linux-scsi] 20101008 [patch] gdth: integer overflow in ioctl (MLIST)
[oss-security] 20101108 Re: CVE request: kernel: gdth: integer overflow in ioc_general() (MLIST)
44648 (BID)
[oss-security] 20101109 Re: CVE request: kernel: gdth: integer overflow in ioc_general() (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=651147 (CONFIRM)
[oss-security] 20101109 Re: CVE request: kernel: gdth: integer overflow in ioc_general() (MLIST)
[oss-security] 20101110 Re: CVE request: kernel: gdth: integer overflow in ioc_general() (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.1 (CONFIRM)
[oss-security] 20101108 CVE request: kernel: gdth: integer overflow in ioc_general() (MLIST)
FEDORA-2010-18983 (FEDORA)
42745 (SECUNIA)
ADV-2010-3321 (VUPEN)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0004 (REDHAT)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
42778 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
ADV-2011-0024 (VUPEN)
SUSE-SA:2010:060 (SUSE)
42789 (SECUNIA)
42932 (SECUNIA)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
SUSE-SA:2011:007 (SUSE)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
ADV-2011-0375 (VUPEN)
ADV-2011-0298 (VUPEN)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f63ae56e4e97fb12053590e41a4fa59e7daa74a4 (MISC)
CVE: CVE-2010-4083
CVE: CVE-2010-4083
Id:
CVE-2010-4083
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4083
Comment
: The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT, or (4) SEM_STAT command in a semctl system call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648673 (CONFIRM)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 (CONFIRM)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[mm-commits] 20100923 + sys_semctl-fix-kernel-stack-leakage.patch added to -mm tree (MLIST)
DSA-2126 (DEBIAN)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0004 (REDHAT)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
ADV-2011-0124 (VUPEN)
SUSE-SA:2010:060 (SUSE)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0024 (VUPEN)
42932 (SECUNIA)
43809 (BID)
42789 (SECUNIA)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
ADV-2011-0375 (VUPEN)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
MDVSA-2011:051 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=982f7c2b2e6a28f8f266e075d92e19c0dd4c6e56 ()
CVE: CVE-2010-4082
CVE: CVE-2010-4082
Id:
CVE-2010-4082
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4082
Comment
: The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a VIAFB_GET_INFO ioctl call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648671 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.36/ChangeLog-2.6.36-rc5 (CONFIRM)
[linux-kernel] 20100915 [PATCH] drivers/video/via/ioctl.c: prevent reading uninitializedstack memory (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
43817 (BID)
SUSE-SA:2011:001 (SUSE)
SUSE-SA:2011:002 (SUSE)
RHSA-2010:0958 (REDHAT)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
42801 (SECUNIA)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4aaa78f4c2f9cde2f335b14f4ca30b01f9651ca ()
CVE: CVE-2010-4081
CVE: CVE-2010-4081
Id:
CVE-2010-4081
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4081
Comment
: The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
[linux-kernel] 20100925 [PATCH] sound/pci/rme9652: prevent reading uninitialized stack memory (MLIST)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.36/ChangeLog-2.6.36-rc6 (CONFIRM)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648670 (CONFIRM)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
45063 (BID)
SUSE-SA:2011:002 (SUSE)
DSA-2126 (DEBIAN)
SUSE-SA:2011:001 (SUSE)
42778 (SECUNIA)
ADV-2011-0012 (VUPEN)
42801 (SECUNIA)
SUSE-SA:2010:060 (SUSE)
RHSA-2011:0017 (REDHAT)
42884 (SECUNIA)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
ADV-2011-0298 (VUPEN)
43291 (SECUNIA)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:008 (SUSE)
SUSE-SA:2011:007 (SUSE)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e68d3b316ab7b02a074edc4f770e6a746390cb7d ()
CVE: CVE-2010-4080
CVE: CVE-2010-4080
Id:
CVE-2010-4080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4080
Comment
: The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSP_IOCTL_GET_CONFIG_INFO ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.36/ChangeLog-2.6.36-rc6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=648669 (CONFIRM)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
[linux-kernel] 20100925 [PATCH] sound/pci/rme9652: prevent reading uninitialized stack memory (MLIST)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
45063 (BID)
45058 (BID)
SUSE-SA:2011:002 (SUSE)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:001 (SUSE)
DSA-2126 (DEBIAN)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
42801 (SECUNIA)
SUSE-SA:2010:060 (SUSE)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
42890 (SECUNIA)
42884 (SECUNIA)
RHSA-2011:0007 (REDHAT)
RHSA-2011:0017 (REDHAT)
SUSE-SA:2011:007 (SUSE)
ADV-2011-0298 (VUPEN)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e68d3b316ab7b02a074edc4f770e6a746390cb7d ()
CVE: CVE-2010-4077
CVE: CVE-2010-4077
Id:
CVE-2010-4077
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4077
Comment
: The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[linux-kernel] 20100915 [PATCH] drivers/char/nozomi.c: prevent reading uninitialized stackmemory (MLIST)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648663 (CONFIRM)
45059 (BID)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
8129 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d281da7ff6f70efca0553c288bb883e8605b3862 ()
CVE: CVE-2010-4076
CVE: CVE-2010-4076
Id:
CVE-2010-4076
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4076
Comment
: The rs_ioctl function in drivers/char/amiserial.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
[linux-kernel] 20100915 [PATCH] drivers/char/amiserial.c: prevent reading uninitialized stack memory (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648661 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d281da7ff6f70efca0553c288bb883e8605b3862 ()
CVE: CVE-2010-4075
CVE: CVE-2010-4075
Id:
CVE-2010-4075
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4075
Comment
: The uart_get_count function in drivers/serial/serial_core.c in the Linux kernel before 2.6.37-rc1 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=648660 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc1 (CONFIRM)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[linux-kernel] 20100915 [PATCH] drivers/serial/serial_core.c: prevent readinguninitialized stack memory (MLIST)
[oss-security] 20100925 CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
RHSA-2010:0958 (REDHAT)
43806 (BID)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
RHSA-2011:0007 (REDHAT)
42884 (SECUNIA)
42890 (SECUNIA)
RHSA-2011:0017 (REDHAT)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d281da7ff6f70efca0553c288bb883e8605b3862 ()
CVE: CVE-2010-4073
CVE: CVE-2010-4073
Id:
CVE-2010-4073
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4073
Comment
: The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c; and the (4) compat_sys_mq_open and (5) compat_sys_mq_getsetattr functions in ipc/compat_mq.c.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc1 (CONFIRM)
[linux-kernel] 20101006 [PATCH v3] IPC: Initialize structure memory to zero for compat functions (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=648658 (CONFIRM)
[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures (MLIST)
45073 (BID)
DSA-2126 (DEBIAN)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:001 (SUSE)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
SUSE-SA:2010:060 (SUSE)
SUSE-SA:2011:004 (SUSE)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
42884 (SECUNIA)
42890 (SECUNIA)
RHSA-2011:0007 (REDHAT)
RHSA-2011:0017 (REDHAT)
ADV-2011-0298 (VUPEN)
ADV-2011-0375 (VUPEN)
SUSE-SA:2011:007 (SUSE)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
MDVSA-2011:029 (MANDRIVA)
MDVSA-2011:051 (MANDRIVA)
8366 (SREASON)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=03145beb455cf5c20a761e8451e30b8a74ba58d9 ()
CVE: CVE-2010-3880
CVE: CVE-2010-3880
Id:
CVE-2010-3880
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3880
Comment
: net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20101104 CVE request: kernel: logic error in INET_DIAG bytecode auditing (MLIST)
[netdev] 20101103 [PATCH 2/2] inet_diag: Make sure we actually run the same bytecode we audited. (MLIST)
44665 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=651264 (CONFIRM)
[oss-security] 20101105 Re: CVE request: kernel: logic error in INET_DIAG bytecode auditing (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
42126 (SECUNIA)
RHSA-2010:0958 (REDHAT)
RHSA-2011:0004 (REDHAT)
DSA-2126 (DEBIAN)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22e76c849d505d87c5ecf3d3e6742a65f0ff4860 (MISC)
CVE: CVE-2010-3874
CVE: CVE-2010-3874
Id:
CVE-2010-3874
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3874
Comment
: Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
787 (Out-of-bounds Write)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=649695 (CONFIRM)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
[oss-security] 20101104 Re: CVE request: kernel: CAN information leak (MLIST)
[netdev] 20101110 can-bcm: fix minor heap overflow (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[oss-security] 20101103 CVE request: kernel: CAN information leak (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101102 [SECURITY] CAN info leak/minor heap overflow (MLIST)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[oss-security] 20101220 CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
FEDORA-2010-18983 (FEDORA)
ADV-2010-3321 (VUPEN)
42745 (SECUNIA)
DSA-2126 (DEBIAN)
SUSE-SA:2011:001 (SUSE)
RHSA-2010:0958 (REDHAT)
SUSE-SA:2011:002 (SUSE)
42801 (SECUNIA)
ADV-2011-0012 (VUPEN)
42778 (SECUNIA)
ADV-2011-0124 (VUPEN)
42932 (SECUNIA)
SUSE-SA:2011:004 (SUSE)
RHSA-2011:0007 (REDHAT)
42890 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
MDVSA-2011:029 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0597d1b99fcfc2c0eada09a698f85ed413d4ba84 (MISC)
CVE: CVE-2010-3859
CVE: CVE-2010-3859
Id:
CVE-2010-3859
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3859
Comment
: Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
[netdev] 20101027 Re: [PATCH 1/4] tipc: Fix bugs in tipc_msg_calc_data_size() (MLIST)
[netdev] 20101027 [PATCH 3/4] tipc: Update arguments to use size_t for iovec array sizes (MLIST)
[netdev] 20101027 [PATCH 1/4] tipc: Fix bugs in tipc_msg_calc_data_size() (MLIST)
[netdev] 20101027 [PATCH 2/4] tipc: Fix bugs in tipc_msg_build() (MLIST)
[netdev] 20101027 [PATCH 4/4] tipc: Fix bugs in sending of large amounts of byte-stream data (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=645867 (CONFIRM)
[oss-security] 20101022 CVE request: kernel: heap overflow in TIPC (MLIST)
[netdev] 20101028 Re: [PATCH 2/4] tipc: Fix bugs in tipc_msg_build() (MLIST)
[netdev] 20101027 [PATCH 0/4] RFC: tipc int vs size_t fixes (MLIST)
[oss-security] 20101022 Re: CVE request: kernel: heap overflow in TIPC (MLIST)
RHSA-2011:0004 (REDHAT)
DSA-2126 (DEBIAN)
ADV-2011-0024 (VUPEN)
42789 (SECUNIA)
44354 (BID)
42963 (SECUNIA)
RHSA-2011:0162 (REDHAT)
ADV-2011-0168 (VUPEN)
MDVSA-2011:029 (MANDRIVA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
[netdev] 20101021 TIPC security issues (MLIST)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=253eacc070b114c2ec1f81b067d2fed7305467b0 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8acfe468b0384e834a303f08ebc4953d72fb690a (MISC)
CVE: CVE-2010-3858
CVE: CVE-2010-3858
Id:
CVE-2010-3858
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3858
Comment
: The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, which allows local users to cause a denial of service (system crash) via a crafted exec system call, a related issue to CVE-2010-2240.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
44301 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=645222 (CONFIRM)
http://grsecurity.net/~spender/64bit_dos.c (MISC)
[oss-security] 20101022 Re: CVE request: kernel: setup_arg_pages: diagnose excessive argument size (MLIST)
15619 (EXPLOIT-DB)
[oss-security] 20101021 CVE request: kernel: setup_arg_pages: diagnose excessive argument size (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 (CONFIRM)
RHSA-2010:0958 (REDHAT)
DSA-2126 (DEBIAN)
RHSA-2011:0004 (REDHAT)
42758 (SECUNIA)
MDVSA-2010:257 (MANDRIVA)
ADV-2011-0070 (VUPEN)
USN-1041-1 (UBUNTU)
42789 (SECUNIA)
ADV-2011-0024 (VUPEN)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1b528181b2ffa14721fb28ad1bd539fe1732c583 (MISC)
CVE: CVE-2010-3297
CVE: CVE-2010-3297
Id:
CVE-2010-3297
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3297
Comment
: The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
909 ()
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc5 (CONFIRM)
41440 (SECUNIA)
https://bugzilla.redhat.com/show_bug.cgi?id=633145 (CONFIRM)
[oss-security] 20100914 CVE request: kernel: numerous infoleaks (MLIST)
[oss-security] 20100914 Re: CVE request: kernel: numerous infoleaks (MLIST)
[linux-kernel] 20100911 [PATCH] drivers/net/eql.c: prevent reading uninitialized stack memory (MLIST)
43229 (BID)
RHSA-2010:0771 (REDHAT)
SUSE-SA:2010:050 (SUSE)
DSA-2126 (DEBIAN)
ADV-2011-0070 (VUPEN)
USN-1041-1 (UBUNTU)
42758 (SECUNIA)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
43161 (SECUNIA)
ADV-2011-0280 (VUPEN)
USN-1057-1 (UBUNTU)
SUSE-SA:2010:052 (SUSE)
MDVSA-2011:051 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=44467187dc22fdd33a1a06ea0ba86ce20be3fe3c (MISC)
CVE: CVE-2010-3296
CVE: CVE-2010-3296
Id:
CVE-2010-3296
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3296
Comment
: The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20100914 Re: CVE request: kernel: numerous infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=633149 (CONFIRM)
[linux-kernel] 20100911 [PATCH] drivers/net/cxgb3/cxgb3_main.c: prevent reading uninitialized stack memory (MLIST)
[oss-security] 20100914 CVE request: kernel: numerous infoleaks (MLIST)
41440 (SECUNIA)
43221 (BID)
SUSE-SA:2010:050 (SUSE)
DSA-2126 (DEBIAN)
USN-1041-1 (UBUNTU)
42758 (SECUNIA)
ADV-2011-0070 (VUPEN)
42884 (SECUNIA)
RHSA-2011:0017 (REDHAT)
ADV-2011-0298 (VUPEN)
SUSE-SA:2011:007 (SUSE)
SUSE-SA:2010:054 (SUSE)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=49c37c0334a9b85d30ab3d6b5d1acb05ef2ef6de (MISC)
Content available only for registered users!
ovaldb@altx-soft.com