CVE-2010-4161
published 2010-12-30CVE-2010-4161: The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.51%
40.7th percentile
The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by sending UDP traffic to a socket that has a crafted socket filter, a related issue to CVE-2010-4158.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| redhat | enterprise_linux | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Red Hat
kernel: rhel5 commit 6865201191 caused deadlock
vendor_redhat·2010-11-10·CVSS 2.1
CVE-2010-4161 [LOW] kernel: rhel5 commit 6865201191 caused deadlock
kernel: rhel5 commit 6865201191 caused deadlock
The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by sending UDP traffic to a socket that has a crafted socket filter, a related issue to CVE-2010-4158.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not backport the upstream commit 93821778 that introduced this. It did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they have backported the upstream commit fda9ef5d that addressed this. Future kernel update in Red Hat Enterprise Linux 5 may addres
GHSA
GHSA-jch4-5383-w2vq: The udp_queue_rcv_skb function in net/ipv4/udp
ghsa_unreviewed·2022-05-14·CVSS 2.1
CVE-2010-4161 [LOW] GHSA-jch4-5383-w2vq: The udp_queue_rcv_skb function in net/ipv4/udp
The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by sending UDP traffic to a socket that has a crafted socket filter, a related issue to CVE-2010-4158.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4161 kernel: rhel5 commit 6865201191 caused deadlock
bugzilla·2010-11-12·CVSS 2.1
CVE-2010-4161 [LOW] CVE-2010-4161 kernel: rhel5 commit 6865201191 caused deadlock
CVE-2010-4161 kernel: rhel5 commit 6865201191 caused deadlock
Using the reproducer for CVE-2010-4158,
BUG: soft lockup - CPU#2 stuck for 60s! [a.out:4362]
CPU 2:
Modules linked in: autofs4 hidp rfcomm l2cap bluetooth lockd sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf ipv6 xfrm_nalgo crypto_api loop dm_multipath scsi_dh video backlight sbs power_meter hwmon i2c_ec i2c_core dell_wmi wmi button battery asus_acpi acpi_memhotplug ac parport_pc lp parport joydev ixgbe floppy bnx2 8021q ide_cd sr_mod i5000_edac serio_raw dca edac_mc tpm_tis cdrom tpm tpm_bios sg pcspkr dm_raid45 dm_message dm_region_hash dm_mem_cache dm_snapshot dm_zero dm_mirror dm_log dm_mod usb_storage ata_piix libata shpchp megaraid_sas sd_mod scsi_mod ext3 jbd uhci_hcd ohci_hcd ehci_hcd
Pid: 4362, comm: a.out Not t
Bugzilla
CVE-2010-4158 kernel: socket filters infoleak
bugzilla·2010-11-10·CVSS 2.1
CVE-2010-4158 [LOW] CVE-2010-4158 kernel: socket filters infoleak
CVE-2010-4158 kernel: socket filters infoleak
Description of problem:
The "mem" array used as scratch space for socket filters is not initialized, allowing unprivileged users to leak kernel stack bytes.
http://www.spinics.net/lists/netdev/msg146361.html
http://lists.grok.org.uk/pipermail/full-disclosure/2010-November/077321.html
Acknowledgements:
Red Hat would like to thank Dan Rosenberg for reporting this issue.
Discussion:
This issue has been assigned the name CVE-2010-4158.
---
We are aware that the public reproducer caused a deadlock issue on rhel-5. We have filed separate bugs for that. See CVE-2010-4161.
---
Upstream commit:
http://git.kernel.org/linus/57fe93b374a6b8711995c2d466c502af9f3a08bb
---
This issue has been addressed in following products:
MRG for RHEL-5
Via RH
http://secunia.com/advisories/42789http://secunia.com/advisories/46397http://www.redhat.com/support/errata/RHSA-2011-0004.htmlhttp://www.securityfocus.com/archive/1/514845http://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.spinics.net/lists/netdev/msg146404.htmlhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0024https://bugzilla.redhat.com/show_bug.cgi?id=651698https://bugzilla.redhat.com/show_bug.cgi?id=652534https://exchange.xforce.ibmcloud.com/vulnerabilities/64497http://secunia.com/advisories/42789http://secunia.com/advisories/46397http://www.redhat.com/support/errata/RHSA-2011-0004.htmlhttp://www.securityfocus.com/archive/1/514845http://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.spinics.net/lists/netdev/msg146404.htmlhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0024https://bugzilla.redhat.com/show_bug.cgi?id=651698https://bugzilla.redhat.com/show_bug.cgi?id=652534https://exchange.xforce.ibmcloud.com/vulnerabilities/64497
2010-12-30
Published