CVE-2010-0291: Medium severity Linux Linux kernel vulnerability
Description of problem: There's a pile of upstream commits that fixed issues that can lead to user-triggerable panics on supported boxes: http://groups.google.com/group/linux.kernel/msg/895f20870532241e.
54f5de709984bae0d31d823ff03de755f9dcac54 ecc1a8993751de4e82eb18640d631dae1f626bd6 1a0ef85f84feb13f07b604fcf5b90ef7c2b5c82f f106af4e90eadd76cfc0b5325f659619e08fb762 097eed103862f9c6a97f2e415e21d1134017b135 935874141df839c706cd6cdc438e85eb69d1525e 0ec62d290912bb4b989be7563851bc364ec73b56 c4caa778157dbbf04116f0ac2111e389b5cd7a29 2ea1d13f64efdf49319e86c87d9ba38c30902782 570dcf2c15463842e384eb597a87c1e39bead99b 564b3bffc619dcbdd160de597b0547a7017ea010 0067bd8a55862ac9dd212bd1c4f6f5bff1ca1301 f8b7256096a20436f6d0926747e3ac3d64c81d24 8c7b49b3ecd48923eb64ff57e07a1cdb74782970 9206de95b1ea68357996ec02be5db0638a0de2c1 2c6a10161d0b5fc047b5bd81b03693b9af99fab5 05d72faa6d13c9d857478a5d35c85db9adada685 bb52d6694002b9d632bb355f64daa045c6293a4e e77414e0aad6a1b063ba5e5750c582c75327ea6a aa65607373a4daf2010e8c3867b6317619f3c1a3
http://groups.google.co.jp/group/fa.linux.kernel/browsethread/thread/8bf22336b1082090
Other sources
The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "domremap() mess" or "mremap/mmap mess."
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0291?
CVE-2010-0291 is classified as a high severity vulnerability due to its potential to cause user-triggerable panics.
Which software versions are affected by CVE-2010-0291?
CVE-2010-0291 affects Linux Kernel versions up to 2.6.32.4 and Debian GNU/Linux versions 4.0 and 5.0.
How do I fix CVE-2010-0291?
To fix CVE-2010-0291, update the Linux Kernel to a patched version that addresses the identified issues.
What type of vulnerability is CVE-2010-0291?
CVE-2010-0291 is a kernel panic vulnerability that can be triggered by users.
Is there a workaround for CVE-2010-0291?
There are no specific workarounds for CVE-2010-0291; the recommended action is to apply the necessary patches.