cbcvebase.
CVE-2010-3437
published 2010-10-04

CVE-2010-3437: Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain…

medium6.6CVSS 3.1
AVLACLAuNCCINAC
EXPLOIT
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
linuxlinux_kernel< 2.6.362.6.36
linuxlinux_kernel
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_real_time_extension
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit

CVSS provenance

nvd6.6MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:C
vulncheck6.6MEDIUM