Release date: 2010-06-17
Updated on:
Affected Systems:
Linux kernel 2.6.x
Unaffected system:
Linux kernel 2.6.35
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42527
Cve id: CVE-2010-2943
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel xfs implements Multi-tree allocation without querying inode before reading the inode buffer. authenticated users can read disconnected files by accessing the expired NFS file handle, you can also read or overwrite the disk blocks that are currently allocated to active files but previously allocated to disconnected files.
<* Source: Dave Chinner (dchinner@redhat.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 624923
Https://www.redhat.com/support/errata/RHSA-2010-0723.html
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://oss.sgi.com/archives/xfs/2010-06/msg00191.html
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = 7b6259e7a83647948fa33a736cc832310c8d85aa
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2010: 0723-01) and patch:
RHSA-2010: 0723-01: Important: kernel security and bug fix update
Link: https://www.redhat.com/support/errata/RHSA-2010-0723.html