cbcvebase.
CVE-2010-2478
published 2010-09-29

CVE-2010-2478: Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a…

high7.2CVSS 3.1
AVLACLAuNCCICAC
Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value that triggers a buffer overflow, a different vulnerability than CVE-2010-3084.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
linuxlinux_kernel< 2.6.362.6.36
linuxlinux_kernel< 2.6.33.72.6.33.7
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_real_time_extension
suselinux_enterprise_server