The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-09-03T19:00:00

Updated: 2024-08-07T02:25:07.361Z

Reserved: 2010-06-09T00:00:00

Link: CVE-2010-2226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-09-03T20:00:03.340

Modified: 2023-02-13T04:20:30.060

Link: CVE-2010-2226

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-06-17T00:00:00Z

Links: CVE-2010-2226 - Bugzilla