{"cves":["CVE-2010-3904","CVE-2010-3067","CVE-2010-3477"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"Following security bugs are fixed in this errata\n\nCVE-2010-3904\nWhen copying data to userspace, the RDS protocol failed to verify that the user-provided address was a valid\nuserspace address.  A local unprivileged user could issue specially crafted socket calls to write arbitrary\nvalues into kernel memory and potentially escalate privileges to root.\n\nCVE-2010-3067\nInteger overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows\nlocal users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit\nsystem call.\n\nCVE-2010-3477\nThe tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing\nfunctionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which\nallows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump\noperation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.\n\nkernel:\n\n[2.6.32-100.21.1.el5]\n- [rds] fix access issue with rds (Chris Mason) {CVE-2010-3904}\n- [fuse] linux-2.6.32-fuse-return-EGAIN-if-not-connected-bug-10154489.patch\n- [net] linux-2.6.32-net-sched-fix-kernel-leak-in-act_police.patch\n- [aio] linux-2.6.32-aio-check-for-multiplication-overflow-in-do_io_subm.patch\n\nofa:\n\n[1.5.1-4.0.23]\n- Fix rds permissions checks during copies\n\n[1.5.1-4.0.21]\n- Update to BXOFED 1.5.1-1.3.6-5","id":"ELSA-2010-2009","ovalId":"oval:com.oracle.elsa:def:20102009","source":"oracle_linux","title":"ELSA-2010-2009:  Oracle Linux 5 Unbreakable Enterprise kernel security fix update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2010-2009.html"}