Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 325567 (CVE-2010-1436) - Kernel: gfs2_quota struct DOS (CVE-2010-1436)
Summary: Kernel: gfs2_quota struct DOS (CVE-2010-1436)
Status: RESOLVED FIXED
Alias: CVE-2010-1436
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: [ linux <= 2.6.18 ? ]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-25 19:54 UTC by Stefan Behte (RETIRED)
Modified: 2013-09-15 19:38 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 19:54:41 UTC
CVE-2010-1436 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1436):
  gfs2 in the Linux kernel 2.6.18, and possibly other versions, does
  not properly handle when the gfs2_quota struct occupies two separate
  pages, which allows local users to cause a denial of service (kernel
  panic) via certain manipulations that cause an out-of-bounds write,
  as demonstrated by writing from an ext3 file system to a gfs2 file
  system.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 21:37:48 UTC
CVE-2010-1436 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1436):
  gfs2 in the Linux kernel 2.6.18, and possibly other versions, does
  not properly handle when the gfs2_quota struct occupies two separate
  pages, which allows local users to cause a denial of service (kernel
  panic) via certain manipulations that cause an out-of-bounds write,
  as demonstrated by writing from an ext3 file system to a gfs2 file
  system.