HIGH · 7.8

CVE-2010-2798

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users...

Vulnerability Description

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.35
VmwareEsx4.0
CanonicalUbuntu Linux6.06
DebianDebian Linux5.0
AvayaAura Communication Manager5.2
AvayaAura Presence Services6.0
AvayaAura Session Manager1.1
AvayaAura System Manager5.2
AvayaAura System Platform1.1
AvayaIq5.0
AvayaVoice Portal5.0
OpensuseOpensuse11.1
SuseLinux Enterprise High Availability Extension11
SuseSuse Linux Enterprise Desktop11
SuseSuse Linux Enterprise Server11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2798?

CVE-2010-2798 is a vulnerability with a CVSS score of 7.8 (HIGH). The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users...

How severe is CVE-2010-2798?

CVE-2010-2798 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2798?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Vmware Esx, Canonical Ubuntu Linux, Debian Debian Linux, Avaya Aura Communication Manager.