CVE-2010-4258
published 2010-12-30CVE-2010-4258: The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass…
PriorityP333medium6.2CVSS 2.0
AVLACHAuNCCICAC
EXPLOIT
EPSS
2.66%
84.1th percentile
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 2.6.36.2 | 2.6.36.2 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_ubuntu7.8HIGH
vendor_redhat6.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities (i.MX51)
vendor_ubuntu·2011-07-06·CVSS 7.2
CVE-2010-4529 [HIGH] Linux kernel vulnerabilities (i.MX51)
Title: Linux kernel vulnerabilities (i.MX51)
Summary: Multiple kernel flaws have been fixed.
Thomas Pollet discovered that the RDS network protocol did not check
certain iovec buffers. A local attacker could exploit this to crash the
system or possibly execute arbitrary code as the root user. (CVE-2010-3865)
Dan Rosenberg discovered that the Linux kernel X.25 implementation
incorrectly parsed facilities. A remote attacker could exploit this to
crash the kernel, leading to a denial of service. (CVE-2010-3873)
Dan Rosenberg discovered that the CAN protocol on 64bit systems did not
correctly calculate the size of certain buffers. A local attacker could
exploit this to crash the system or possibly execute arbitrary code as the
root user. (CVE-2010-3874)
Vasiliy Kulikov discovered that the
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 7.8
CVE-2010-4164 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple flaws fixed in the Linux kernel.
Dan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If
a system was using X.25, a remote attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2010-4164)
Vegard Nossum discovered that memory garbage collection was not handled
correctly for active sockets. A local attacker could exploit this to
allocate all available kernel memory, leading to a denial of service.
(CVE-2010-4249)
Nelson Elhage discovered that the kernel did not correctly handle process
cleanup after triggering a recoverable kernel bug. If a local attacker were
able to trigger certain kinds of kernel bugs, they could create a specially
crafted process to gain root privileges. (CVE-2010
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-04-20·CVSS 4.9
CVE-2010-2954 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hawkes discovered that the Linux kernel did not correctly validate
memory ranges on 64bit kernels when allocating memory on behalf of 32bit
system calls. On a 64bit system, a lo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-04-05·CVSS 1.9
CVE-2010-4075 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Dan Rosenberg discovered that multiple terminal ioctls did not correctly
initialize structure memory. A local attacker could exploit this to read
portions of kernel stack memory, leading to a loss of privacy.
(CVE-2010-4075)
Dan Rosenberg discovered that the socket filters did not correctly
initialize structure memory. A local attacker could create malicious
filters to read portions of kernel stack memory, leading to a loss of
privacy. (CVE-2010-4158)
Dan Rosenberg discovered that certain iovec operations did not calculate
page counts correctly. A local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2010-4162)
Dan Rosenberg discovered that the SCSI subsystem did not correctly val
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)
vendor_ubuntu·2011-03-25·CVSS 7.2
CVE-2010-2478 [HIGH] Linux Kernel vulnerabilities (Marvell Dove)
Title: Linux Kernel vulnerabilities (Marvell Dove)
Summary: An attacker could send crafted input to the kernel and cause it to
crash.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hutchings discovered that the ethtool interface did not correctly check
certain sizes. A local attacker could perform malicious ioctl calls that
could crash the system, leadin
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 4.7
CVE-2009-4895 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges. (CVE-2010-3904)
Nelson Elhage discovered several problems with the Acorn Econet protocol
driver. A local user could cause a denial of service via a NULL pointer
dereference, escalate privileges by overflowing the kernel stack, and
assign Econet addresses to arbitrary interfaces. (CVE-2010-3848,
CVE-2010-3849, CVE-2010-3850)
Ben Hawkes discovered that the Linux kernel did not correctly filter
registers on 64bit kernels when performing 32bit system calls. On a 64bit
system, a local attacker could manipulate 32bit system calls to gain root
privileges. (CVE-2010-3301)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-02-01·CVSS 4.6
CVE-2010-4079 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel vulnerablilities.
Gleb Napatov discovered that KVM did not correctly check certain privileged
operations. A local attacker with access to a guest kernel could exploit
this to crash the host system, leading to a denial of service.
(CVE-2010-0435)
Dan Rosenberg discovered that the Linux kernel TIPC implementation
contained multiple integer signedness errors. A local attacker could
exploit this to gain root privileges. (CVE-2010-3859)
Dan Rosenberg discovered that the Linux kernel X.25 implementation
incorrectly parsed facilities. A remote attacker could exploit this to
crash the kernel, leading to a denial of service. (CVE-2010-3873)
Dan Rosenberg discovered that the CAN protocol on 64bit systems did not
correctly calculate th
Red Hat
kernel: failure to revert address limit override in OOPS error path
vendor_redhat·2010-12-03·CVSS 6.2
CVE-2010-4258 [MEDIUM] kernel: failure to revert address limit override in OOPS error path
kernel: failure to revert address limit override in OOPS error path
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
Statement: The Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG enabled the panic_on_oops sysctl tunable by default, and therefore are not affected by this issue. However, as a preventive measure (for example, for administrators who have turned panic_on_oops off),
GHSA
GHSA-vj6j-hh8w-8qxh: The do_exit function in kernel/exit
ghsa_unreviewed·2022-05-13
CVE-2010-4258 [MEDIUM] CWE-269 GHSA-vj6j-hh8w-8qxh: The do_exit function in kernel/exit
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
No detection rules found.
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [mrg-1.3]
bugzilla·2010-12-03·CVSS 6.2
CVE-2010-4258 [MEDIUM] CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [mrg-1.3]
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [mrg-1.3]
Verified by code review.
Found bz659574_CVE-2010-4258-do_exit-check-is-run-with-get_fs-USER_DS.patch applied to kernel-rt-2.6.33.7-rt29.52.src.rpm, from upstream commit 33dd94ae1ccbfb7bf0fb6c692bc3d1c4269e6177.
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2011-0330.html
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path
bugzilla·2010-12-03·CVSS 4.7
CVE-2010-4258 [MEDIUM] CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path
Nelson discovered an interesting interaction in the Linux kernel between the clear_child_tid feature of clone(2), and the set_fs() function used internally in the kernel to temporarily disable access_ok() checking of userspace pointers.
Under some (not totally uncommon) circumstances, it is possible for a user to leverage this interaction to turn a kernel oops or BUG() into a write of an integer 0 to a user-controlled address in kernel memory.
This is known to be exploited with CVE-2010-3849 - http://www.redhat.com/security/data/cve/CVE-2010-3849.html.
Acknowledgements:
Red Hat would like to thank Nelson Elhage for reporting this issue.
Discussion:
This needs oops to first trigger the mm_release path w
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-5.6]
bugzilla·2010-12-03·CVSS 6.2
CVE-2010-4258 [MEDIUM] CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-5.6]
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-5.6]
Confirmed that patch has been added to latest kernel-2.6.18-238.el5.
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2011-0017.html
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
bugzilla·2010-12-03·CVSS 6.2
CVE-2010-4258 [MEDIUM] CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
A patch addressing this issue has been included in kernel 2.6.9-89.34.1.EL.
Discussion:
Reproduced in 2.6.9-89.33.EL and -89.34.EL. Verified in 2.6.9-89.34.1.EL.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2011-0162.html
http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0086.htmlhttp://blog.nelhage.com/2010/12/cve-2010-4258-from-dos-to-privesc/http://code.google.com/p/chromium-os/issues/detail?id=10234http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=33dd94ae1ccbfb7bf0fb6c692bc3d1c4269e6177http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.htmlhttp://marc.info/?l=linux-kernel&m=129117048916957&w=2http://openwall.com/lists/oss-security/2010/12/02/2http://openwall.com/lists/oss-security/2010/12/02/3http://openwall.com/lists/oss-security/2010/12/02/4http://openwall.com/lists/oss-security/2010/12/02/7http://openwall.com/lists/oss-security/2010/12/08/4http://openwall.com/lists/oss-security/2010/12/08/5http://openwall.com/lists/oss-security/2010/12/08/9http://openwall.com/lists/oss-security/2010/12/09/14http://openwall.com/lists/oss-security/2010/12/09/4http://secunia.com/advisories/42745http://secunia.com/advisories/42778http://secunia.com/advisories/42801http://secunia.com/advisories/42932http://secunia.com/advisories/43056http://secunia.com/advisories/43291http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2http://www.mandriva.com/security/advisories?name=MDVSA-2011:029http://www.vupen.com/english/advisories/2010/3321http://www.vupen.com/english/advisories/2011/0012http://www.vupen.com/english/advisories/2011/0124http://www.vupen.com/english/advisories/2011/0213http://www.vupen.com/english/advisories/2011/0298http://www.vupen.com/english/advisories/2011/0375https://bugzilla.redhat.com/show_bug.cgi?id=659567https://lkml.org/lkml/2010/12/1/543http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0086.htmlhttp://blog.nelhage.com/2010/12/cve-2010-4258-from-dos-to-privesc/http://code.google.com/p/chromium-os/issues/detail?id=10234http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=33dd94ae1ccbfb7bf0fb6c692bc3d1c4269e6177http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.htmlhttp://marc.info/?l=linux-kernel&m=129117048916957&w=2http://openwall.com/lists/oss-security/2010/12/02/2http://openwall.com/lists/oss-security/2010/12/02/3http://openwall.com/lists/oss-security/2010/12/02/4http://openwall.com/lists/oss-security/2010/12/02/7http://openwall.com/lists/oss-security/2010/12/08/4http://openwall.com/lists/oss-security/2010/12/08/5http://openwall.com/lists/oss-security/2010/12/08/9http://openwall.com/lists/oss-security/2010/12/09/14http://openwall.com/lists/oss-security/2010/12/09/4http://secunia.com/advisories/42745http://secunia.com/advisories/42778http://secunia.com/advisories/42801http://secunia.com/advisories/42932http://secunia.com/advisories/43056http://secunia.com/advisories/43291http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2http://www.mandriva.com/security/advisories?name=MDVSA-2011:029http://www.vupen.com/english/advisories/2010/3321http://www.vupen.com/english/advisories/2011/0012http://www.vupen.com/english/advisories/2011/0124http://www.vupen.com/english/advisories/2011/0213http://www.vupen.com/english/advisories/2011/0298http://www.vupen.com/english/advisories/2011/0375https://bugzilla.redhat.com/show_bug.cgi?id=659567https://lkml.org/lkml/2010/12/1/543
2010-12-30
Published