|
|
| |
|
| |
kernel: multiple vulnerabilities
| Package(s): | kernel |
CVE #(s): | CVE-2010-2478
CVE-2010-2495
|
| Created: | July 9, 2010 |
Updated: | March 28, 2011 |
| Description: |
From the Red Hat bugzilla:
On a 32-bit machine, info.rule_cnt >= 0x40000000 leads to integer overflow and the buffer may be smaller than needed. Since ETHTOOL_GRXCLSRLALL is
unprivileged, this can presumably be used for at least denial of service. (CVE-2010-2478)
From the Red Hat bugzilla:
When transmitting L2TP frames, we derive the outgoing interface's UDP checksum
hardware assist capabilities from the tunnel dst dev. This can sometimes be
NULL, especially when routing protocols are used and routing changes occur.
This patch just checks for NULL dst or dev pointers when checking for netdev
hardware assist features. (CVE-2010-2495)
|
| Alerts: |
|
( Log in to post comments)
|
|
|