CVE-2010-0453: Input Validation

Published Feb 3, 2010
·
Updated

The ucodeioctl function in intel/io/ucodedrv.c in Sun Solaris 10 and OpenSolaris snv69 through snv133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODEGETVERSION IOCTL, which triggers a NULL pointer dereference in the ucodegetrev function, related to retrieval of the microcode revision.

Affected Software

66 affected components
Sun OpenSolaris=snv_127
Sun OpenSolaris=snv_70
Sun OpenSolaris=snv_114
Sun OpenSolaris=snv_90
Sun OpenSolaris=snv_93
Sun OpenSolaris=snv_110
Sun OpenSolaris=snv_85
Sun OpenSolaris=snv_116
Sun OpenSolaris=snv_120
Sun OpenSolaris=snv_72
Sun OpenSolaris=snv_117
Sun OpenSolaris=snv_87
Sun OpenSolaris=snv_123
Sun OpenSolaris=snv_92
Sun OpenSolaris=snv_131
Sun OpenSolaris=snv_77
Sun OpenSolaris=snv_126
Sun OpenSolaris=snv_80
Sun OpenSolaris=snv_130
Sun OpenSolaris=snv_119
Sun OpenSolaris=snv_103
Sun OpenSolaris=snv_84
Sun OpenSolaris=snv_121
Sun OpenSolaris=snv_106
Sun OpenSolaris=snv_86
Sun OpenSolaris=snv_100
Sun OpenSolaris=snv_112
Sun OpenSolaris=snv_89
Sun OpenSolaris=snv_124
Sun OpenSolaris=snv_129
Sun OpenSolaris=snv_78
Sun OpenSolaris=snv_96
Sun OpenSolaris=snv_132
Sun OpenSolaris=snv_99
Sun OpenSolaris=snv_107
Sun OpenSolaris=snv_79
Sun OpenSolaris=snv_122
Sun OpenSolaris=snv_115
Sun OpenSolaris=snv_69
Sun OpenSolaris=snv_98
Sun OpenSolaris=snv_109
Sun OpenSolaris=snv_113
Sun OpenSolaris=snv_71
Sun OpenSolaris=snv_82
Sun OpenSolaris=snv_102
Sun OpenSolaris=snv_105
Sun OpenSolaris=snv_108
Sun OpenSolaris=snv_75
Sun OpenSolaris=snv_81
Sun OpenSolaris=snv_128
Sun OpenSolaris=snv_95
Sun OpenSolaris=snv_133
Sun OpenSolaris=snv_88
Sun OpenSolaris=snv_73
Sun OpenSolaris=snv_104
Sun OpenSolaris=snv_94
Sun OpenSolaris=snv_101
Sun OpenSolaris=snv_83
Sun OpenSolaris=snv_97
Sun OpenSolaris=snv_125
Sun OpenSolaris=snv_74
Sun OpenSolaris=snv_111
Sun OpenSolaris=snv_91
Sun OpenSolaris=snv_76
Sun OpenSolaris=snv_118
Sun Solaris=10.0

Event History

Feb 3, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-0453?

The severity of CVE-2010-0453 is classified as medium due to its ability to cause a denial of service.

2

How do I fix CVE-2010-0453?

To fix CVE-2010-0453, you should update to a patched version of Sun Solaris or OpenSolaris that addresses this vulnerability.

3

Who is affected by CVE-2010-0453?

CVE-2010-0453 affects local users on Sun Solaris 10 and OpenSolaris snv_69 through snv_133, specifically on x86 architectures.

4

What impact does CVE-2010-0453 have on systems?

CVE-2010-0453 can trigger a system panic, resulting in a denial of service for affected systems.

5

Is there a workaround for CVE-2010-0453?

There is no widely known workaround for CVE-2010-0453; updating the software is the recommended approach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203