CVE-2010-3067 (retired)

Priority
Description
Integer overflow in the do_io_submit function in fs/aio.c in the Linux
kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial
of service or possibly have unspecified other impact via crafted use of the
io_submit system call.
Ubuntu-Description
Tavis Ormandy discovered that the AIO subsystem did not correctly validate
certain parameters. A local attacker could exploit this to crash the system
or possibly gain root privileges.
Assigned-to
sconklin
Package
Upstream:released (2.6.36~rc5)
Package
Upstream:released (2.6.36~rc5)
Package
Upstream:released (2.6.36~rc5)
Package
Upstream:released (2.6.36~rc5)
More Information

Updated: 2019-03-26 11:52:43 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)