CVE-2010-4163Improper Input Validation in Kernel

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 75.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 13

Description

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hcm9-3rrf-2f37: The blk_rq_map_user_iov function in block/blk-map2022-05-13
CVEList
CVE-2010-4163: The blk_rq_map_user_iov function in block/blk-map2011-01-03

📋Vendor Advisories

11
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel (i.MX51) vulnerabilities2011-09-13
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities2011-04-05
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25

💬Community

1
Bugzilla
CVE-2010-4163 CVE-2010-4668 kernel: panic when submitting certain 0-length I/O requests2010-11-13
CVE-2010-4163 — Improper Input Validation in Kernel | cvebase