Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 325599 (CVE-2010-1643)

Summary: Kernel: mm/shmem.c knfsd NULL pointer dereference (CVE-2010-1643)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: hardened, kernel
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=595970
Whiteboard: [ linux < 2.6.28-rc3 ]
Package list:
Runtime testing required: ---

Description Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 20:58:41 UTC
CVE-2010-1643 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1643):
  mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict
  overcommit is enabled, does not properly handle the export of shmemfs
  objects by knfsd, which allows attackers to cause a denial of service
  (NULL pointer dereference and knfsd crash) or possibly have
  unspecified other impact via unknown vectors.