CVE-2010-2943
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 17.01% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- linux/linux kernel · canonical/ubuntu linux · vmware/esx · avaya/aura communication manager · avaya/aura presence services · avaya/aura session manager · avaya/aura system manager · avaya/aura system platform · avaya/aura voice portal · avaya/iq
- Source
- secalert@redhat.com
References
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33767Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33768Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33769Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33771Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1920779e67cbf5ea8afef317777c5bf2b8096188
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7124fe0a5b619d65b739477b3b55a20bf805b06d
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7b6259e7a83647948fa33a736cc832310c8d85aa
- http://oss.sgi.com/archives/xfs/2010-06/msg00191.htmlBroken Link
- http://oss.sgi.com/archives/xfs/2010-06/msg00198.htmlBroken Link
- http://secunia.com/advisories/42758Broken Link
- http://secunia.com/advisories/43161Broken Link
- http://secunia.com/advisories/46397Broken Link
- http://support.avaya.com/css/P8/documents/100113326Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35Broken Link
- http://www.openwall.com/lists/oss-security/2010/08/18/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/08/19/5Mailing List, Patch, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0723.htmlBroken Link
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/42527Exploit, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1041-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1057-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2011/0070Broken Link
- http://www.vupen.com/english/advisories/2011/0280Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=624923Issue Tracking, Patch, Third Party Advisory
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33767Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33768Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33769Broken Link
- http://article.gmane.org/gmane.comp.file-systems.xfs.general/33771Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1920779e67cbf5ea8afef317777c5bf2b8096188
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.