CVE-2010-3079NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 68.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 13

Description

kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Also affects: Ubuntu Linux 10.04, 10.10, 9.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-24rh-37mj-9hr5: kernel/trace/ftrace2022-05-13
CVEList
CVE-2010-3079: kernel/trace/ftrace2010-09-30

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25

💬Community

1
Bugzilla
CVE-2010-3079 kernel: ftrace NULL ptr deref2010-09-08
CVE-2010-3079 — NULL Pointer Dereference in Kernel | cvebase