Back

LOW

kernel: IB/uverbs: Handle large number of entries in poll CQ

Published Feb 18, 2011

Description

The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 18, 2011
Updated Aug 6, 2024
Reserved Feb 18, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 8, 2010