Release date: 2010-07-29
Updated on: 2010-09-13
Affected Systems:
Linux kernel 2.6.x
Unaffected system:
Linux kernel 2.6.35
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42237
Cve id: CVE-2010-2492
Linux Kernel is the Kernel used by open source Linux.
In the Linux Kernel eCryptfs subsystem, fs/ecryptfs/messaging. assume that the second parameter of the hash_long () function is the number of hash buckets rather than the number of hash bits. This allows local users to cause buffer overflow.
<* Source: Andre Osterhues (aosterhues@escrypt.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 611385
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = a6f80fb7b5986fda663d94079d3bba0937a6b6ff