Release date: 2010-08-17
Updated on: 2010-08-23
Affected Systems:
Linux kernel 2.6.x
Unaffected system:
Linux kernel 2.6.35.2
Linux kernel 2.6.34.4
Linux kernel 2.6.32.19
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2010-2240
Linux Kernel is the Kernel used by open source Linux.
The memory manager of Linux Kernel does not correctly process when the application can increase the stack to the neighboring memory area. Local Users can gain permission elevation through attacks on X server.
<* Source: Rafal Wojtczuk
Link: http://secunia.com/advisories/40965/
Https://lists.ubuntu.com/archives/ubuntu-security-announce/2010-August/001143.html
Https://www.redhat.com/support/errata/RHSA-2010-0631.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = 320b2b8de12698082609ebbc1a17165727f4c893
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2010: 0631-01) and patch:
RHSA-2010: 0631-01: Important: kernel-rt security and bug fix update
Link: https://www.redhat.com/support/errata/RHSA-2010-0631.html
Ubuntu
------
Ubuntu has released a Security Bulletin (USN-974-1) and patches for this:
USN-974-1: Linux kernel vulnerabilities
Link: https://lists.ubuntu.com/archives/ubuntu-security-announce/2010-August/001143.html