CVE-2010-2538: Integer Overflow
Published Sep 30, 2010
·Updated
Integer overflow in the btrfsioctlclone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFSIOCCLONERANGE ioctl call.
Affected Software
8 affected components
debian/linux-2.6
Linux Linux kernel<2.6.35
Canonical Ubuntu Linux=10.10
Canonical Ubuntu Linux=9.10
Canonical Ubuntu Linux=10.04
SUSE Linux Enterprise Desktop=11-sp1
SUSE Linux Enterprise Server=11-sp1
SUSE Linux Enterprise High Availability Extension=11-sp1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 30, 2010
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:51 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:39 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2538?
CVE-2010-2538 is classified as a medium severity vulnerability.
2
How do I fix CVE-2010-2538?
To fix CVE-2010-2538, upgrade to a version of the Linux kernel that is higher than 2.6.35.
3
What systems are affected by CVE-2010-2538?
CVE-2010-2538 affects various versions of the Linux kernel, including those used by Debian and Ubuntu distributions.
4
What type of attack does CVE-2010-2538 facilitate?
CVE-2010-2538 may allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
5
Is CVE-2010-2538 still exploitable in recent Linux kernels?
CVE-2010-2538 is not exploitable in Linux kernels after version 2.6.35.