Vulnerability Intelligence Report
CVE-2010-2798
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| vmware | esx | 4.0, 4.1 |
| canonical | ubuntu_linux | 6.06, 8.04, 9.04, 9.10, 10.04, 10.10 |
| debian | debian_linux | 5.0 |
| avaya | aura_communication_manager | 5.2 |
| avaya | aura_presence_services | 6.0, 6.1, 6.1.1 |
| avaya | aura_session_manager | 1.1, 5.2, 6.0 |
| avaya | aura_system_manager | 5.2, 6.0, 6.1, 6.1.1 |
| avaya | aura_system_platform | 1.1, 6.0 |
| avaya | iq | 5.0, 5.1 |
| avaya | voice_portal | 5.0, 5.1 |
| opensuse | opensuse | 11.1 |
| suse | linux_enterprise_high_availability_extension | 11 |
| suse | suse_linux_enterprise_desktop | 11 |
| suse | suse_linux_enterprise_server | 11 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.414%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2010-07-22T00:00:00 |
| Published | 2010-09-08T19:00:00 |
| Patch Date | 2010-08-01 |
| Last Updated | 2024-08-07T02:46:48 |
Community Chatter & Buzz