4.9
CVE-2010-4243
- EPSS 0.91%
- Veröffentlicht 22.01.2011 22:00:04
- Zuletzt bearbeitet 16.06.2026 23:24:25
- CVE-Watchlists
- Unerledigt
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 2.6.37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.553 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
http://secunia.com/advisories/46397
http://www.securityfocus.com/archive/1/520102/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
http://secunia.com/advisories/42884
http://www.redhat.com/support/errata/RHSA-2011-0017.html
http://grsecurity.net/~spender/64bit_dos.c
http://www.exploit-db.com/exploits/15619
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c
http://linux.derkeiler.com/Mailing-Lists/Kernel/2010-11/msg13278.html
http://lkml.org/lkml/2010/8/27/429
http://lkml.org/lkml/2010/8/29/206
http://lkml.org/lkml/2010/8/30/138
http://lkml.org/lkml/2010/8/30/378
http://openwall.com/lists/oss-security/2010/11/22/15
http://openwall.com/lists/oss-security/2010/11/22/6
http://www.securityfocus.com/bid/45004
https://bugzilla.redhat.com/show_bug.cgi?id=625688
https://exchange.xforce.ibmcloud.com/vulnerabilities/64700