4.9

CVE-2010-4169

Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 2.6.37
Linux ≫ Linux Kernel Version 2.6.37 Update -
Linux ≫ Linux Kernel Version 2.6.37 Update rc1
Fedoraproject ≫ Fedora Version 13
Opensuse ≫ Opensuse Version 11.3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp1
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
Third Party Advisory
Mailing List
http://www.vupen.com/english/advisories/2011/0298
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/42778
Third Party Advisory
http://www.vupen.com/english/advisories/2011/0012
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/42932
Third Party Advisory
http://www.vupen.com/english/advisories/2011/0124
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.html
Third Party Advisory
http://secunia.com/advisories/42745
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0958.html
Third Party Advisory
http://www.vupen.com/english/advisories/2010/3321
Third Party Advisory
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2
Broken Link
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=63bfd7384b119409685a17d5c58f0b56e5dc03da
http://marc.info/?l=oss-security&m=128979684911295&w=2
Patch
Third Party Advisory
http://marc.info/?l=oss-security&m=128984344103497&w=2
Patch
Third Party Advisory
http://www.securityfocus.com/bid/44861
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=651671
Patch
Third Party Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/63316
Third Party Advisory
VDB Entry