fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-09-29T16:00:00

Updated: 2024-08-07T02:55:45.371Z

Reserved: 2010-08-04T00:00:00

Link: CVE-2010-2946

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-09-29T17:00:04.307

Modified: 2023-02-13T04:21:21.083

Link: CVE-2010-2946

cve-icon Redhat

No data.