MEDIUM
kernel: btrfs: fix checks in BTRFS_IOC_CLONE_RANGE
Published Sep 30, 2010
5.5
MEDIUMCVSS 3.1
EPSS 0.38%
Description
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
Affected products
No data.
Configuration 1
- < 2.6.35
Configuration 2
OR
- 9.10
- 10.04
- 10.10
Configuration 3
OR
- 11
- 11
- 11
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2ebc3464781ad24474abcbd2274e6254689853b5 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://secunia.com/advisories/42758 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35 x_refsource_CONFIRMBroken Link
- http://www.openwall.com/lists/oss-security/2010/07/21/10 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2010/07/21/4 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/41854 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1041-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2011/0070 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2010-2538 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=616998 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-2538
- https://www.cve.org/CVERecord?id=CVE-2010-2538
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 30, 2010
Updated Aug 7, 2024
Reserved Jun 30, 2010
Link CVE-2010-2538
CISA Vulnrichment
Updated n/a