Jump to content

Advisories MDVSA-2010:030: kernel


paul
 Share

Recommended Posts

Some vulnerabilities were discovered and corrected in the Linux

2.6 kernel:

 

Array index error in the gdth_read_event function in

drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows

local users to cause a denial of service or possibly gain privileges

via a negative event index in an IOCTL request. (CVE-2009-3080)

 

The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the

Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified

impact via a crafted HDLC packet that arrives over ISDN and triggers

a buffer under-read. (CVE-2009-4005)

 

An issue was discovered in 2.6.32.x kernels, which sets unsecure

permission for devtmpfs file system by default. (CVE-2010-0299)

 

Additionally, it was added support for Atheros AR2427 Wireless

Network Adapter.

 

To update your kernel, please follow the directions located at:

 

http://www.mandriva.com/en/security/kernelupdate

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...