Description
Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
Published: 2010-12-10
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2010-4133 Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
Ubuntu USN Ubuntu USN USN-1041-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1071-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1072-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1073-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1083-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-1093-1 Linux Kernel vulnerabilities (Marvell Dove)
Ubuntu USN Ubuntu USN USN-1164-1 Linux kernel vulnerabilities (i.MX51)
Ubuntu USN Ubuntu USN USN-1202-1 Linux kernel (OMAP4) vulnerabilities
References
Link Providers
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f63ae56e4e97fb12053590e41a4fa59e7daa74a4 cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html cve-icon cve-icon
http://ns3.spinics.net/lists/linux-scsi/msg47361.html cve-icon cve-icon
http://openwall.com/lists/oss-security/2010/11/09/1 cve-icon cve-icon
http://openwall.com/lists/oss-security/2010/11/09/3 cve-icon cve-icon
http://openwall.com/lists/oss-security/2010/11/09/4 cve-icon cve-icon
http://openwall.com/lists/oss-security/2010/11/09/5 cve-icon cve-icon
http://openwall.com/lists/oss-security/2010/11/10/12 cve-icon cve-icon
http://secunia.com/advisories/42745 cve-icon cve-icon
http://secunia.com/advisories/42778 cve-icon cve-icon
http://secunia.com/advisories/42789 cve-icon cve-icon
http://secunia.com/advisories/42801 cve-icon cve-icon
http://secunia.com/advisories/42932 cve-icon cve-icon
http://secunia.com/advisories/42963 cve-icon cve-icon
http://secunia.com/advisories/43291 cve-icon cve-icon
http://secunia.com/advisories/46397 cve-icon cve-icon
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.1 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0958.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0004.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0162.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/520102/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/44648 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2011-0012.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3321 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0012 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0024 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0124 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0168 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0298 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0375 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=651147 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-4157 cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-4157 cve-icon
History

No history.

Subscriptions

Fedoraproject Fedora
Linux Linux Kernel
Opensuse Opensuse
Redhat Enterprise Linux Enterprise Mrg
Suse Linux Enterprise Desktop Linux Enterprise Real Time Extension Linux Enterprise Server Linux Enterprise Software Development Kit
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T03:34:37.354Z

Reserved: 2010-11-04T00:00:00.000Z

Link: CVE-2010-4157

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-12-10T19:00:05.877

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-4157

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-11-08T00:00:00Z

Links: CVE-2010-4157 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses