{
  "cves": [
    "CVE-2010-3904",
    "CVE-2010-3067",
    "CVE-2010-3477"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "Following security bugs are fixed in this errata\n\nCVE-2010-3904\nWhen copying data to userspace, the RDS protocol failed to verify that the user-provided address was a valid\nuserspace address.  A local unprivileged user could issue specially crafted socket calls to write arbitrary\nvalues into kernel memory and potentially escalate privileges to root.\n\nCVE-2010-3067\nInteger overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows\nlocal users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit\nsystem call.\n\nCVE-2010-3477\nThe tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing\nfunctionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which\nallows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump\noperation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.\n\nkernel:\n\n[2.6.32-100.21.1.el5]\n- [rds] fix access issue with rds (Chris Mason) {CVE-2010-3904}\n- [fuse] linux-2.6.32-fuse-return-EGAIN-if-not-connected-bug-10154489.patch\n- [net] linux-2.6.32-net-sched-fix-kernel-leak-in-act_police.patch\n- [aio] linux-2.6.32-aio-check-for-multiplication-overflow-in-do_io_subm.patch\n\nofa:\n\n[1.5.1-4.0.23]\n- Fix rds permissions checks during copies\n\n[1.5.1-4.0.21]\n- Update to BXOFED 1.5.1-1.3.6-5",
  "id": "ELSA-2010-2009",
  "ovalId": "oval:com.oracle.elsa:def:20102009",
  "source": "oracle_linux",
  "title": "ELSA-2010-2009:  Oracle Linux 5 Unbreakable Enterprise kernel security fix update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2010-2009.html"
}