CVE-2010-1643
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2010
Last modified:
11/04/2025
Description
mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:rc2:*:*:*:*:*:* | 2.6.28 (including) | |
cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba%3Dcommit%3Bh%3D731572d39fcd3498702eda4600db4c43d51e0b26
- http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html
- http://secunia.com/advisories/40645
- http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-knfsd-9666
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc3
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A198
- http://www.openwall.com/lists/oss-security/2010/05/26/2
- http://www.openwall.com/lists/oss-security/2010/05/26/6
- http://www.securityfocus.com/bid/40377
- http://www.vupen.com/english/advisories/2010/1857
- https://bugzilla.redhat.com/show_bug.cgi?id=595970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58957
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba%3Dcommit%3Bh%3D731572d39fcd3498702eda4600db4c43d51e0b26
- http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html
- http://secunia.com/advisories/40645
- http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-knfsd-9666
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc3
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A198
- http://www.openwall.com/lists/oss-security/2010/05/26/2
- http://www.openwall.com/lists/oss-security/2010/05/26/6
- http://www.securityfocus.com/bid/40377
- http://www.vupen.com/english/advisories/2010/1857
- https://bugzilla.redhat.com/show_bug.cgi?id=595970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58957