SB2010122901 - Denial of service in Linux kernel bfa
Published: December 29, 2010 Updated: June 13, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Initialization (CVE-ID: CVE-2010-4343)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper initialization in drivers/scsi/bfa/bfa_core.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- http://www.openwall.com/lists/oss-security/2010/12/08/3
- http://www.spinics.net/lists/linux-scsi/msg43772.html
- https://bugzilla.redhat.com/show_bug.cgi?id=661182
- http://www.openwall.com/lists/oss-security/2010/12/09/15
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35
- http://www.securityfocus.com/bid/45262
- http://www.redhat.com/support/errata/RHSA-2011-0017.html
- http://secunia.com/advisories/42884
- http://secunia.com/advisories/46397
- http://www.vmware.com/security/advisories/VMSA-2011-0012.html
- http://www.securityfocus.com/archive/1/520102/100/0/threaded
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7873ca4e4401f0ecd8868bf1543113467e6bae61