CVE-2010-1451
published 2010-05-07CVE-2010-1451: The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a…
PriorityP411low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.52%
41.3th percentile
The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.33 | 2.6.33 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat2.1LOW
vendor_ubuntu1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-08-04·CVSS 1.2
CVE-2008-7256 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple security flaws.
Junjiro R. Okajima discovered that knfsd did not correctly handle
strict overcommit. A local attacker could exploit this to crash knfsd,
leading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were
affected.) (CVE-2008-7256, CVE-2010-1643)
Chris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did
not correctly handle invalid parameters. A remote attacker could send
specially crafted traffic that could crash the system, leading to a
denial of service. (CVE-2010-1173)
Mario Mikocevic discovered that GFS2 did not correctly handle certain
quota structures. A local attacker could exploit this to crash the
system, leading to a denial of service. (Ubuntu 6.06 LTS was not
affected.) (CVE-2010-1436)
Toshi
Red Hat
CVE-2010-1451: The TSB I-TLB load implementation in arch/sparc/kernel/tsb
vendor_redhat·CVSS 2.1
CVE-2010-1451 [LOW] CVE-2010-1451: The TSB I-TLB load implementation in arch/sparc/kernel/tsb
The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.
Statement: Not vulnerable. This issue did not affect the versions of the Linux kernel as
shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG. Red Hat does not provide support for the Linux kernel on the SPARC architecture.
GHSA
GHSA-37fx-p8jg-8c9r: The TSB I-TLB load implementation in arch/sparc/kernel/tsb
ghsa_unreviewed·2022-05-02
CVE-2010-1451 [LOW] CWE-787 GHSA-37fx-p8jg-8c9r: The TSB I-TLB load implementation in arch/sparc/kernel/tsb
The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=linux-sparc&m=126662159602378&w=2http://marc.info/?l=linux-sparc&m=126662196902830&w=2http://secunia.com/advisories/39830http://www.debian.org/security/2010/dsa-2053http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33http://www.openwall.com/lists/oss-security/2010/02/24/1http://www.openwall.com/lists/oss-security/2010/05/05/2http://marc.info/?l=linux-sparc&m=126662159602378&w=2http://marc.info/?l=linux-sparc&m=126662196902830&w=2http://secunia.com/advisories/39830http://www.debian.org/security/2010/dsa-2053http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33http://www.openwall.com/lists/oss-security/2010/02/24/1http://www.openwall.com/lists/oss-security/2010/05/05/2
2010-05-07
Published