CVE-2010-1088
Vulnerability Summary
Timeline
Description
fs/namei.c in Linux kernel 2.6.18 through 2.6.34 does not always follow NFS automount "symlinks," which allows attackers to have an unknown impact, related to LOOKUP_FOLLOW.
CVSS Metrics
- v2.0•MEDIUM•Score: 5.4AV:N/AC:H/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 1.83%• Percentile: 83%
Affected Systems
- linux•linux_kernel
2.6.18 | 2.6.18.1 | 2.6.18.2 | 2.6.18.3 | 2.6.18.4 | 2.6.18.5 | 2.6.18.6 | 2.6.18.7 | 2.6.18.8 | 2.6.19 | 2.6.19.1 | 2.6.19.2 | 2.6.19.3 | 2.6.19.4 | 2.6.19.5 | 2.6.19.6 | 2.6.19.7 | 2.6.20 | 2.6.20.1 | 2.6.20.2 | 2.6.20.3 | 2.6.20.4 | 2.6.20.5 | 2.6.20.6 | 2.6.20.7 | 2.6.20.8 | 2.6.20.9 | 2.6.20.10 | 2.6.20.11 | 2.6.20.12 | 2.6.20.13 | 2.6.20.14 | 2.6.20.15 | 2.6.20.16 | 2.6.20.17 | 2.6.20.18 | 2.6.20.19 | 2.6.20.20 | 2.6.20.21 | 2.6.21 | 2.6.21.1 | 2.6.21.2 | 2.6.21.3 | 2.6.21.4 | 2.6.21.5 | 2.6.21.6 | 2.6.21.7 | 2.6.22 | 2.6.22.1 | 2.6.22.2 | 2.6.22.3 | 2.6.22.4 | 2.6.22.5 | 2.6.22.6 | 2.6.22.7 | 2.6.22.8 | 2.6.22.9 | 2.6.22.10 | 2.6.22.11 | 2.6.22.12 | 2.6.22.13 | 2.6.22.14 | 2.6.22.15 | 2.6.22.16 | 2.6.22.17 | 2.6.22.18 | 2.6.22.19 | 2.6.23 | 2.6.23.1 | 2.6.23.2 | 2.6.23.3 | 2.6.23.4 | 2.6.23.5 | 2.6.23.6 | 2.6.23.7 | 2.6.23.8 | 2.6.23.9 | 2.6.23.10 | 2.6.23.11 | 2.6.23.12 | 2.6.23.13 | 2.6.23.14 | 2.6.23.15 | 2.6.23.16 | 2.6.23.17 | 2.6.24 | 2.6.24:rc1 | 2.6.24:rc2 | 2.6.24:rc3 | 2.6.24:rc4 | 2.6.24:rc5 | 2.6.24.1 | 2.6.24.2 | 2.6.24.3 | 2.6.24.4 | 2.6.24.5 | 2.6.24.6 | 2.6.24.7 | 2.6.25 | 2.6.25.1 | 2.6.25.2 | 2.6.25.3 | 2.6.25.4 | 2.6.25.5 | 2.6.25.6 | 2.6.25.7 | 2.6.25.8 | 2.6.25.9 | 2.6.25.10 | 2.6.25.11 | 2.6.25.12 | 2.6.25.13 | 2.6.25.14 | 2.6.25.15 | 2.6.25.16 | 2.6.25.17 | 2.6.25.18 | 2.6.25.19 | 2.6.25.20 | 2.6.26 | 2.6.26.1 | 2.6.26.2 | 2.6.26.3 | 2.6.26.4 | 2.6.26.5 | 2.6.26.6 | 2.6.26.7 | 2.6.26.8 | 2.6.27 | 2.6.27:rc1 | 2.6.27:rc2 | 2.6.27:rc3 | 2.6.27:rc4 | 2.6.27:rc5 | 2.6.27:rc6 | 2.6.27:rc7 | 2.6.27:rc8 | 2.6.27:rc9 | 2.6.27.1 | 2.6.27.2 | 2.6.27.3 | 2.6.27.4 | 2.6.27.5 | 2.6.27.6 | 2.6.27.7 | 2.6.27.8 | 2.6.27.9 | 2.6.27.10 | 2.6.27.11 | 2.6.27.12 | 2.6.27.13 | 2.6.27.14 | 2.6.27.15 | 2.6.27.16 | 2.6.27.17 | 2.6.27.18 | 2.6.27.19 | 2.6.27.20 | 2.6.27.21 | 2.6.27.22 | 2.6.27.23 | 2.6.27.24 | 2.6.27.25 | 2.6.27.26 | 2.6.27.27 | 2.6.27.28 | 2.6.27.29 | 2.6.27.30 | 2.6.27.31 | 2.6.27.32 | 2.6.27.33 | 2.6.27.34 | 2.6.27.35 | 2.6.27.36 | 2.6.27.37 | 2.6.27.38 | 2.6.27.39 | 2.6.27.40 | 2.6.27.41 | 2.6.27.42 | 2.6.27.43 | 2.6.27.44 | 2.6.27.45 | 2.6.28 | 2.6.28.1 | 2.6.28.2 | 2.6.28.3 | 2.6.28.4 | 2.6.28.5 | 2.6.28.6 | 2.6.28.7 | 2.6.28.8 | 2.6.28.9 | 2.6.28.10 | 2.6.29 | 2.6.29.1 | 2.6.29.2 | 2.6.29.3 | 2.6.29.4 | 2.6.29.5 | 2.6.29.6 | 2.6.30 | 2.6.30.1 | 2.6.30.2 | 2.6.30.3 | 2.6.30.4 | 2.6.30.5 | 2.6.30.6 | 2.6.30.7 | 2.6.30.8 | 2.6.30.9 | 2.6.30.10 | 2.6.31 | 2.6.31:rc1 | 2.6.31:rc2 | 2.6.31:rc3 | 2.6.31:rc4 | 2.6.31:rc5 | 2.6.31:rc6 | 2.6.31:rc7 | 2.6.31:rc8 | 2.6.31.1 | 2.6.31.2 | 2.6.31.3 | 2.6.31.4 | 2.6.31.5 | 2.6.31.6 | 2.6.31.7 | 2.6.31.8 | 2.6.31.9 | 2.6.31.10 | 2.6.31.11 | 2.6.31.12 | 2.6.31.13 | 2.6.32 | 2.6.32.1 | 2.6.32.2 | 2.6.32.3 | 2.6.32.4 | 2.6.32.5 | 2.6.32.6 | 2.6.32.7 | 2.6.32.8 | 2.6.32.9 | 2.6.32.10 | 2.6.32.11 | 2.6.33 | 2.6.34 | 2.6.34:rc1 | 2.6.34:rc2 | 2.6.34:rc3 | 2.6.34:rc4
References (15)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=ac278a9c505092dd82077a2446af8f9fc0d9c095
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:198
- http://www.openwall.com/lists/oss-security/2010/02/24/3
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:088
- http://www.securityfocus.com/bid/39044
- http://secunia.com/advisories/43315
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10093
- http://www.novell.com/linux/security/advisories/2010_23_kernel.html
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://secunia.com/advisories/39742
- https://bugzilla.redhat.com/show_bug.cgi?id=567813
- http://www.debian.org/security/2010/dsa-2053
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://secunia.com/advisories/39830