CVE-2010-4243: Medium severity Linux Linux kernel vulnerability
Description of problem: This issue was mentioned in http://grsecurity.net/~spender/64bitdos.c. Written in the comments: "The second bug here is that the memory usage explodes within the kernel from a single 128k allocation in userland The explosion of memory isn't accounted for by any task so it won't be terminated by the OOM killer."
Acknowledgements:
Red Hat would like to thank Brad Spengler for reporting this issue.
Other sources
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Ki ...
— Debian
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4243?
CVE-2010-4243 has been classified as a medium severity vulnerability that can lead to excessive memory consumption in the kernel.
How do I fix CVE-2010-4243?
To fix CVE-2010-4243, users should upgrade to a kernel version later than 2.6.37 where the vulnerability has been addressed.
What systems are affected by CVE-2010-4243?
CVE-2010-4243 affects the Linux kernel versions up to and including 2.6.37 as well as the user-mode-linux package.
What type of vulnerability is CVE-2010-4243?
CVE-2010-4243 is a memory allocation vulnerability that can cause memory usage to increase significantly within the Linux kernel.
Can CVE-2010-4243 be exploited remotely?
CVE-2010-4243 does not indicate remote exploitation capabilities and is primarily a local privilege escalation issue.