cbcvebase.
CVE-2010-2943
published 2010-09-30

CVE-2010-2943: The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote…

PriorityP357high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EXPLOIT
EPSS
17.01%
96.7th percentile
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
avayaaura_communication_manager
avayaaura_presence_services
avayaaura_presence_services
avayaaura_presence_services
avayaaura_session_manager
avayaaura_session_manager
avayaaura_session_manager
avayaaura_system_manager
avayaaura_system_manager
avayaaura_system_manager
avayaaura_system_manager
avayaaura_system_platform
avayaaura_system_platform
avayaaura_voice_portal
avayaaura_voice_portal
avayaiq
avayaiq
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
linuxlinux_kernel< 2.6.352.6.35
vmwareesx
vmwareesx
vmwarevmware_esxi

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.