CVE-2010-3298
published 2010-09-30CVE-2010-3298: The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.41%
33.3th percentile
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.36 | 2.6.36 |
| linux | linux_kernel | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu7.2HIGH
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)
vendor_ubuntu·2011-03-25·CVSS 7.2
CVE-2010-2478 [HIGH] Linux Kernel vulnerabilities (Marvell Dove)
Title: Linux Kernel vulnerabilities (Marvell Dove)
Summary: An attacker could send crafted input to the kernel and cause it to
crash.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hutchings discovered that the ethtool interface did not correctly check
certain sizes. A local attacker could perform malicious ioctl calls that
could crash the system, leadin
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 4.7
CVE-2009-4895 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hawkes discovered that the Linux kernel did not correctly filter
registers on 64bit kernels when performing 32bit system calls. On a 64bit
system, a local attacker could manipulate 32bit system calls to gain root
privileges. (CVE-2010-3301)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-02-28·CVSS 4.7
CVE-2009-4895 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hawkes discovered that the Linux kernel did not correctly filter
registers on 64bit kernels when performing 32bit system calls. On a 64bit
system, a local attacker could manipulate 32bit system calls to gain root
privileges. (CVE-2010-3301)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-02-25·CVSS 4.7
CVE-2009-4895 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Al Viro discovered a race condition in the TTY driver. A local attacker
could exploit this to crash the system, leading to a denial of service.
(CVE-2009-4895)
Dan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly
check file permissions. A local attacker could overwrite append-only files,
leading to potential data loss. (CVE-2010-2066)
Dan Rosenberg discovered that the swapexit xfs ioctl did not correctly
check file permissions. A local attacker could exploit this to read from
write-only files, leading to a loss of privacy. (CVE-2010-2226)
Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory
manager did not properly handle when applications grow stacks into adjacent
memory regi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-01-10·CVSS 7.1
CVE-2010-3698 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple security flaws in Linux kernel.
Louis Rilling and Matthieu Fertré reported a use after free error in the
Linux kernel's futex_wait function. A local user could exploit this flaw to
cause a denial of service (system crash) or possibly gain privileges via a
specially crafted application. (CVE-2014-0205)
Ben Hawkes discovered that the Linux kernel did not correctly filter
registers on 64bit kernels when performing 32bit system calls. On a 64bit
system, a local attacker could manipulate 32bit system calls to gain root
privileges. (CVE-2010-3301)
Dan Rosenberg discovered that the btrfs filesystem did not correctly
validate permissions when using the clone function. A local attacker could
overwrite the contents of file handles that were o
Red Hat
kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
vendor_redhat·2010-09-11·CVSS 2.1
CVE-2010-3298 [LOW] kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and 5, as they did not support USB Option High Speed Mobile Devices. This was addressed in Red Hat Enterprise Linux Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2010-0771.html.
GHSA
GHSA-j939-hwr4-9qqc: The hso_get_count function in drivers/net/usb/hso
ghsa_unreviewed·2022-05-13
CVE-2010-3298 [LOW] CWE-200 GHSA-j939-hwr4-9qqc: The hso_get_count function in drivers/net/usb/hso
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3298 kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
bugzilla·2010-09-13·CVSS 2.1
CVE-2010-3298 [LOW] CVE-2010-3298 kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
CVE-2010-3298 kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory
Description of problem:
http://lkml.org/lkml/2010/9/11/167
The TIOCGICOUNT device ioctl allows unprivileged users to read 9 bytes of uninitialized stack memory, because the "reserved" member of the serial_icounter_struct struct declared on the stack in hso_get_count() is not altered or zeroed before being copied back to the user. This patch takes care of it.
Acknowledgements:
Red Hat would like to thank Dan Rosenberg for reporting this issue.
Discussion:
Commit in David Miller's tree is
7011e660938fc44ed86319c18a5954e95a82ab3e
---
Statement:
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and 5, as they did not support USB Option High Speed Mobile
Bugzilla
CVE-2010-2939 openssl: double-free vulnerability in ssl3_get_key_exchange()
bugzilla·2010-08-11·CVSS 4.3
CVE-2010-2939 [MEDIUM] CVE-2010-2939 openssl: double-free vulnerability in ssl3_get_key_exchange()
CVE-2010-2939 openssl: double-free vulnerability in ssl3_get_key_exchange()
George Guninski reported [1] a double-free flaw in openssl's client implementation that could lead to a crash when ECDH is used. It was reported against 1.0.0a but the code being patched [2] to correct the flaw has also been identified in 0.9.8 [3].
[1] http://marc.info/?l=openssl-dev&m=128118163216952&w=2
[2] http://marc.info/?l=openssl-dev&m=128128256314328&w=2
[3] http://article.gmane.org/gmane.comp.security.oss.general/3298
Discussion:
I'm not 100% sure of the impact here as it looks like it might just be in the openssl client. I don't know if this code is used by other clients linked to the openssl libraries or not, so at this point cannot say if other applications are impacted by this.
---
Except this c
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=7011e660938fc44ed86319c18a5954e95a82ab3ehttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://lkml.org/lkml/2010/9/11/167http://secunia.com/advisories/41440http://secunia.com/advisories/42758http://secunia.com/advisories/42890http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc5http://www.openwall.com/lists/oss-security/2010/09/14/2http://www.openwall.com/lists/oss-security/2010/09/14/7http://www.redhat.com/support/errata/RHSA-2011-0007.htmlhttp://www.securityfocus.com/bid/43226http://www.ubuntu.com/usn/USN-1041-1http://www.vupen.com/english/advisories/2011/0070http://www.vupen.com/english/advisories/2011/0298https://bugzilla.redhat.com/show_bug.cgi?id=633140http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=7011e660938fc44ed86319c18a5954e95a82ab3ehttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://lkml.org/lkml/2010/9/11/167http://secunia.com/advisories/41440http://secunia.com/advisories/42758http://secunia.com/advisories/42890http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc5http://www.openwall.com/lists/oss-security/2010/09/14/2http://www.openwall.com/lists/oss-security/2010/09/14/7http://www.redhat.com/support/errata/RHSA-2011-0007.htmlhttp://www.securityfocus.com/bid/43226http://www.ubuntu.com/usn/USN-1041-1http://www.vupen.com/english/advisories/2011/0070http://www.vupen.com/english/advisories/2011/0298https://bugzilla.redhat.com/show_bug.cgi?id=633140
2010-09-30
Published