Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-2798

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 2.6.35之前版本存在代码问题漏洞,该漏洞源于gfs2_dirent_find_space函数在与sentinel目录条目相关的计算中使用了不正确的大小值,从而导致系统拒绝服务。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.41% · P35
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-2798

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 2.6.35之前版本存在代码问题漏洞,该漏洞源于gfs2_dirent_find_space函数在与sentinel目录条目相关的计算中使用了不正确的大小值,从而导致系统拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-2798

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-2798

登录查看更多情报信息。

Patches & Fixes for CVE-2010-2798 (1)

Vendor Advisories for CVE-2010-2798 (8)

Mailing List Discussions for CVE-2010-2798 (4)

Other References for CVE-2010-2798 (5)

Same Patch Batch · n/a · 2010-09-08 · 15 CVEs total

CVE-2010-2066 Linux kernel 'mext_check_arguments'函数权限许可和访问控制问题漏洞
CVE-2010-2492 Linux kernel 缓冲区错误漏洞
CVE-2010-2524 Linux kernel CIFS DNS解析功能设计错误漏洞
CVE-2010-2960 Linux kernel 'keyctl_session_to_parent'函数空指针应用错误漏洞
CVE-2009-4895 Linux kernel 'tty_fasync'函数竞争条件漏洞
CVE-2010-2495 Linux kernel 代码问题漏洞
CVE-2010-2803 Linux kenerl 'drm_ioctl'函数信息泄露漏洞
CVE-2010-2955 Linux kernel 'cfg80211_wext_giwessid'函数程序设计漏洞
CVE-2010-2958 phpMyAdmin 'libraries/Error.class.php'脚本跨站脚本攻击漏洞
CVE-2010-2959 Linux kernel 'net/can/bcm.c'函数整数溢出漏洞
CVE-2010-3004 HP Operations Agent未明安全漏洞
CVE-2010-3005 HP Operations Agent未明权限许可和访问控制漏洞
CVE-2010-3198 Zope ZServer设计错误漏洞
CVE-2010-3264 Novell Identity Manager引擎安装程序信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2010-2798

No comments yet


Leave a comment