Description
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2153-1 | linux-2.6 security update |
EUVD |
EUVD-2010-4231 | The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call. |
Ubuntu USN |
USN-1054-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1083-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1093-1 | Linux Kernel vulnerabilities (Marvell Dove) |
Ubuntu USN |
USN-1105-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1111-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1119-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1164-1 | Linux kernel vulnerabilities (i.MX51) |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Suse
Subscribe
Linux Enterprise Desktop
Subscribe
Linux Enterprise Real Time Extension
Subscribe
Linux Enterprise Server
Subscribe
Linux Enterprise Software Development Kit
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T03:34:37.991Z
Reserved: 2010-11-16T00:00:00.000Z
Link: CVE-2010-4258
No data.
Status : Deferred
Published: 2010-12-30T19:00:04.410
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-4258
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN