First published: Fri Dec 10 2010(Updated: )
Last updated 24 July 2024
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
debian/user-mode-linux | ||
Linux kernel | =2.6.37-rc4 | |
Linux kernel | =2.6.37-rc2 | |
Linux kernel | =2.6.37-rc5 | |
Linux kernel | =2.6.37-rc1 | |
Linux kernel | =2.6.37-rc3 | |
Linux kernel | <2.6.37 | |
Linux kernel | =2.6.37 | |
Linux Kernel | <2.6.37 | |
Linux Kernel | =2.6.37 | |
Linux Kernel | =2.6.37-rc1 | |
Linux Kernel | =2.6.37-rc2 | |
Linux Kernel | =2.6.37-rc3 | |
Linux Kernel | =2.6.37-rc4 | |
Linux Kernel | =2.6.37-rc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4346 is considered to have a medium severity due to the potential for local users to bypass mmap_min_addr restrictions.
To fix CVE-2010-4346, upgrade to Linux kernel version 2.6.37 or later.
Local users running vulnerable versions of the Linux kernel prior to 2.6.37 are affected by CVE-2010-4346.
CVE-2010-4346 allows for potential NULL pointer dereference attacks due to the failure to call the security_file_mmap function.
CVE-2010-4346 is present in Linux kernel versions prior to 2.6.37-rc6.