CVE-2010-3904

Priority
High
Description
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram
Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36
does not properly validate addresses obtained from user space, which allows
local users to gain privileges via crafted use of the sendmsg and recvmsg
system calls.
Ubuntu-Description
Dan Rosenberg discovered that the RDS network protocol did not correctly
check certain parameters. A local attacker could exploit this gain root
privileges.
References
Bugs
Notes
jdstrand> per tracking bug LP: #712610, there was a regression in the kernel
in -proposed for linux-mvl-dove. It it being investigated.
Assigned-to
sconklin
Package
Upstream:not-affected
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-309.18)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-216.33)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.35-25.44~lucid1)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:needed
Ubuntu 8.04 LTS (Hardy Heron):not-affected
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-25.45)
Ubuntu 11.04 (Natty Narwhal):not-affected
Patches:
Karmic:http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3904/patches/karmic/linux/0001-Local-privilege-escalation-vulnerability-in-RDS-socket.txt
Lucid:http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3904/patches/lucid/linux/0001-Local-privilege-escalation-vulnerability-in-RDS-socket.txt
Maverick:http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3904/patches/maverick/linux/0001-Local-privilege-escalation-vulnerability-in-RDS-socket.txt
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.31-608.22)
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):not-affected
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:21:30 UTC (commit 5347)