SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2943

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned…

HIGH 8.1EPSS 17.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 17.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
17.01% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
linux/linux kernel · canonical/ubuntu linux · vmware/esx · avaya/aura communication manager · avaya/aura presence services · avaya/aura session manager · avaya/aura system manager · avaya/aura system platform · avaya/aura voice portal · avaya/iq
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.