CVE-2010-3067Integer Overflow or Wraparound in Kernel

Severity
4.9MEDIUMNVD
EPSS
0.2%
top 64.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 13

Description

Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages6 packages

Also affects: Debian Linux 5.0, Ubuntu Linux 10.04, 10.10, 6.06, 8.04, 9.04, 9.10

🔴Vulnerability Details

2
GHSA
GHSA-446w-q44c-4xj9: Integer overflow in the do_io_submit function in fs/aio2022-05-13
CVEList
CVE-2010-3067: Integer overflow in the do_io_submit function in fs/aio2010-09-21

📋Vendor Advisories

6
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25
Ubuntu
Linux kernel vulnerabilities2010-10-19

💬Community

1
Bugzilla
CVE-2010-3067 kernel: do_io_submit() infoleak2010-09-02
CVE-2010-3067 — Integer Overflow or Wraparound | cvebase