CVE-2010-4243
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a…
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://linux.derkeiler.com/Mailing-Lists/Kernel/2010-11/msg13278.htmlBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
- http://www.exploit-db.com/exploits/15619Exploit, Third Party Advisory, VDB Entry
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-0017.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45004Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=625688Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64700VDB Entry
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://linux.derkeiler.com/Mailing-Lists/Kernel/2010-11/msg13278.htmlBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.