Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2010-4256

Published: 25 January 2011

The pipe_fcntl function in fs/pipe.c in the Linux kernel before 2.6.37 does not properly determine whether a file is a named pipe, which allows local users to cause a denial of service via an F_SETPIPE_SZ fcntl call.

From the Ubuntu Security Team

It was discovered that named pipes did not correctly handle certain fcntl calls. A local attacker could exploit this to crash the system, leading to a denial of service.

Notes

AuthorNote
sbeattie
http://openwall.com/lists/oss-security/2010/11/30/6 claims
it was introduced in 2.6.35-rc2
apw
it was introduced by commit 35f3d14dbbc58447c61e38a162ea10add6b31dc7
"pipe: add support for shrinking and growing pipes"
which was introduced in v2.6.35-rc1

Priority

Low

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Not vulnerable

karmic Not vulnerable

lucid Not vulnerable

maverick
Released (2.6.35-25.43)
natty
Released (2.6.37-8.20)
upstream
Released (2.6.37~rc4)
Patches:
upstream: http://git.kernel.org/linus/71993e62a47dabddf10302807d6aa260455503f4
upstream: http://git.kernel.org/linus/c66fb347946ebdd5b10908866ecc9fa05ee2cf3d
linux-ec2
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Ignored
(reached end-of-life)
lucid Not vulnerable

maverick Ignored
(binary supplied by "linux" now)
natty Does not exist

upstream
Released (2.6.37~rc4)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Ignored
(reached end-of-life)
lucid Not vulnerable

maverick Does not exist

natty Does not exist

upstream
Released (2.6.37~rc4)
linux-lts-backport-maverick
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Does not exist

lucid
Released (2.6.35-25.44~lucid1)
maverick Does not exist

natty Does not exist

upstream
Released (2.6.37~rc4)
linux-lts-backport-natty
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Not vulnerable
(2.6.38-1.27~lucid1)
maverick Does not exist

natty Does not exist

upstream
Released (2.6.37~rc4)
linux-mvl-dove
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Ignored
(abandonded branch)
lucid Not vulnerable

maverick Not vulnerable

natty Does not exist

upstream
Released (2.6.37~rc4)
linux-source-2.6.15
Launchpad, Ubuntu, Debian
dapper Not vulnerable

hardy Does not exist

karmic Does not exist

lucid Does not exist

maverick Does not exist

natty Does not exist

upstream
Released (2.6.37~rc4)
linux-ti-omap4
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Does not exist

lucid Does not exist

maverick
Released (2.6.35-903.23)
natty Not vulnerable
(2.6.38-1201.2)
upstream
Released (2.6.37~rc4)