HIGH · 8.1

CVE-2010-2943

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read ...

Vulnerability Description

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.35
CanonicalUbuntu Linux6.06
VmwareEsx4.0
AvayaAura Communication Manager5.2
AvayaAura Presence Services6.0
AvayaAura Session Manager1.1
AvayaAura System Manager5.2
AvayaAura System Platform1.1
AvayaAura Voice Portal5.0
AvayaIq5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2943?

CVE-2010-2943 is a vulnerability with a CVSS score of 8.1 (HIGH). The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read ...

How severe is CVE-2010-2943?

CVE-2010-2943 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2943?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Vmware Esx, Avaya Aura Communication Manager, Avaya Aura Presence Services.