LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2010-1162 CVE-2010-1173 CVE-2010-1187 CVE-2010-1437 CVE-2010-1446 CVE-2010-1451
Created:May 25, 2010 Updated:April 18, 2011
Description: From the Debian advisory:

CVE-2010-1162: Catalin Marinas reported an issue in the tty subsystem that allows local attackers to cause a kernel memory leak, possibly resulting in a denial of service.

CVE-2010-1173: Chris Guo from Nokia China and Jukka Taimisto and Olli Jarva from Codenomicon Ltd reported an issue in the SCTP subsystem that allows a remote attacker to cause a denial of service using a malformed init package.

CVE-2010-1187: Neil Hormon reported an issue in the TIPC subsystem. Local users can cause a denial of service by way of a NULL pointer dereference by sending datagrams through AF_TIPC before entering network mode.

CVE-2010-1437: Toshiyuki Okajima reported a race condition in the keyring subsystem. Local users can cause memory corruption via keyctl commands that access a keyring in the process of being deleted, resulting in a denial of service.

CVE-2010-1446: Wufei reported an issue with kgdb on the PowerPC architecture, allowing local users to write to kernel memory. Note: this issue does not affect binary kernels provided by Debian. The fix is provided for the benefit of users who build their own kernels from Debian source.

CVE-2010-1451: Brad Spengler reported an issue on the SPARC architecture that allows local users to execute non-executable pages.

Alerts:
SUSE SUSE-SA:2011:017 2011-04-18
openSUSE openSUSE-SU-2011:0346-1 2011-04-18
SUSE SUSE-SA:2011:015 2011-03-24
openSUSE openSUSE-SU-2010:0664-1 2010-09-23
Mandriva MDVSA-2010:188 2010-09-23
MeeGo MeeGo-SA-10:15 2010-08-03
CentOS CESA-2010:0474 2010-08-27
CentOS CESA-2010:0474 2010-08-23
Red Hat RHSA-2010:0631-01 2010-08-17
Ubuntu USN-966-1 2010-08-04
Mandriva MDVSA-2010:198 2010-10-07
Red Hat RHSA-2010:0474-01 2010-06-15
Fedora FEDORA-2010-9183 2010-05-28
Debian DSA-2053-1 2010-05-25
MeeGo MeeGo-SA-10:01 2010-07-07
openSUSE openSUSE-SU-2010:0397-1 2010-07-19
CentOS CESA-2010:0504 2010-07-02
SuSE SUSE-SA:2010:027 2010-07-02
Pardus 2010-64 2010-06-04
SUSE SUSE-SA:2010:031 2010-07-20
Red Hat RHSA-2010:0504-01 2010-07-01
Fedora FEDORA-2010-9209 2010-05-28
Ubuntu USN-947-2 2010-06-04
Ubuntu USN-947-1 2010-06-03

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds