CVE-2010-2946: Input Validation
Published Sep 29, 2010
·Updated
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
Affected Software
8 affected components
debian/linux-2.6
Linux Linux kernel<2.6.35.2
Canonical Ubuntu Linux=10.10
Canonical Ubuntu Linux=6.06
Canonical Ubuntu Linux=9.04
Canonical Ubuntu Linux=8.04
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=9.10
Remediation
Event History
Sep 29, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:51 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:39 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2946?
CVE-2010-2946 is considered a moderate vulnerability that could allow local users to bypass extended attribute namespace restrictions.
2
How do I fix CVE-2010-2946?
To remediate CVE-2010-2946, you should upgrade your Linux kernel to version 2.6.35.2 or later.
3
Which versions of the Linux kernel are affected by CVE-2010-2946?
CVE-2010-2946 affects Linux kernels prior to version 2.6.35.2.
4
Can CVE-2010-2946 be exploited remotely?
No, CVE-2010-2946 can only be exploited by local users with access to the system.
5
What types of systems are vulnerable to CVE-2010-2946?
CVE-2010-2946 impacts various Linux distributions, including older Ubuntu and Debian versions.