Affected Versions:
Linux kernel 2.6.x vulnerability description:
Bugtraq id: 42249
Cve id: CVE-2010-2521
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel implements the NFS 4 server XDR with a buffer overflow vulnerability. attackers on the local network can send specially crafted large composite requests to the NFSv4 server, causing the Kernel to be busy and DOs or execute code. <* Reference
Eugene Teo (eugeneteo@eugeneteo.net)
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 612028
Https://www.redhat.com/support/errata/RHSA-2010-0606.html
*>
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = 2bc3c1179c781b359d4f2f3439cb3df72afc17fc
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2010: 0606-01) and patch:
RHSA-2010: 0606-01: Important: kernel security and bug fix update
Link: html> https://www.redhat.com/support/errata/RHSA-2010-0606.html