« Volver al listado

CVE-2010-2960

Estado: ModificadaAlta (7.8)—

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2960",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-09-08T20:00:04.027",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://secunia.com/advisories/41263",
      "tags": [
        "Broken Link"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://securitytracker.com/id?1024384",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://twitter.com/taviso/statuses/22777866582",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/09/02/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/42932",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1000-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0298",
      "tags": [
        "Broken Link"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=627440",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61557",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/41263",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1024384",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://twitter.com/taviso/statuses/22777866582",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/09/02/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/42932",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1000-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0298",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=627440",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61557",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function."
    },
    {
      "lang": "es",
      "value": "La función keyctl_session_to_parent en security/keys/keyctl.c en el kernel de Linux v2.6.35.4 y anteriores, espera que determinados keyrings de sesión aparezcan, lo que permite a usuarios locales provocar una denegación de servicio(deferencia a puntero nulo y caída de sistema) o posiblemente tener otro impacto sin especificar a través del argumento KEYCTL_SESSION_TO_PARENT a la función  keyctl."
    }
  ],
  "lastModified": "2026-06-16T23:21:50.543",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0D2A268-65B0-4233-9DCE-16CEFCE589A3",
              "versionEndExcluding": "2.6.35.4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "454A5D17-B171-4F1F-9E0B-F18D1E5CA9FD"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0507E91-567A-41D6-A7E5-5088A39F75FB"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D026D0-EF78-438D-BEDD-FC8571F3ACEB"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01EDA41C-6B2E-49AF-B503-EB3882265C11"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87614B58-24AB-49FB-9C84-E8DDBA16353B"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10A193CD-12B9-4236-8A2C-E8CEAE592952"
            },
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F691F4E7-2FF1-4EFB-B21F-E510049A9940"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}