CVE-2010-4650

Impact:
Moderate
Public Date:
2010-11-30
Bugzilla:
667892: CVE-2010-4650 kernel: fuse: verify ioctl retries

The MITRE CVE dictionary describes this issue as:

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

Find out more about CVE-2010-4650 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of Linux kernel as shipped with Red
Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit
59efec7b that introduced this issue. It did not affect the version of Linux
kernel as shipped with Red hat Enterprise MRG as it did not provide support
for Character device in Userspace (CUSE). A future kernel update in Red Hat
Enterprise Linux 6 may address this flaw. Note that, by default, the
"/dev/cuse" file in Red Hat Enterprise Linux 6 is only accessible by the
root user.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 4
Base Metrics AV:L/AC:H/Au:N/C:N/I:N/A:C
Access Vector Local
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Enterprise MRG 2 realtime-kernel Not affected
Red Hat Enterprise Linux 6 kernel Will not fix
Red Hat Enterprise Linux 5 kernel Not affected
Red Hat Enterprise Linux 4 kernel Not affected

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.