CVE-2010-4343
Publication date 29 December 2010
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.
From the Ubuntu Security Team
Krishna Gudipati discovered that the bfa adapter driver did not correctly initialize certain structures. A local attacker could read files in /sys to crash the system, leading to a denial of service.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux | ||
| linux-ec2 | ||
| linux-fsl-imx51 | ||
| linux-lts-backport-maverick | ||
| linux-lts-backport-natty | ||
| linux-mvl-dove | ||
| linux-source-2.6.15 | ||
| linux-ti-omap4 | ||
Patch details
| Package | Patch details |
|---|---|
| linux |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-1080-1
- Linux kernel vulnerabilities
- 1 March 2011
- USN-1080-2
- Linux kernel vulnerabilities
- 2 March 2011
- USN-1093-1
- Linux Kernel vulnerabilities (Marvell Dove)
- 25 March 2011