| Summary: | Kernel: KGDB arbitrary kernel memory ovewriting (CVE-2010-1446) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Stefan Behte (RETIRED) <craig> |
| Component: | Kernel | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | hardened-kernel+disabled, hardened, kernel |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | [ linux < 2.6.33 PPC ] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Stefan Behte (RETIRED)
2010-06-25 19:57:43 UTC
CVE-2010-1446 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1446): arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kernel memory, related to Fsl booke. Of the hardened sources, it looks like only hardened-sources-2.6.32-r7 may be vulnerable. It is based on 2.6.32.13. |