CVE-2010-2943
Summary
| CVE | CVE-2010-2943 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-30 15:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle. |
Risk And Classification
Primary CVSS: v3.1 8.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Avaya | Aura Communication Manager | 5.2 | All | All | All |
| Application | Avaya | Aura Presence Services | 6.0 | All | All | All |
| Application | Avaya | Aura Presence Services | 6.1 | All | All | All |
| Application | Avaya | Aura Presence Services | 6.1.1 | All | All | All |
| Application | Avaya | Aura Session Manager | 1.1 | All | All | All |
| Application | Avaya | Aura Session Manager | 5.2 | All | All | All |
| Application | Avaya | Aura Session Manager | 6.0 | All | All | All |
| Application | Avaya | Aura System Manager | 5.2 | All | All | All |
| Application | Avaya | Aura System Manager | 6.0 | All | All | All |
| Application | Avaya | Aura System Manager | 6.1 | All | All | All |
| Application | Avaya | Aura System Manager | 6.1.1 | All | All | All |
| Application | Avaya | Aura System Platform | 1.1 | All | All | All |
| Application | Avaya | Aura System Platform | 6.0 | - | All | All |
| Application | Avaya | Aura System Platform | 6.0 | sp1 | All | All |
| Application | Avaya | Aura Voice Portal | 5.0 | All | All | All |
| Application | Avaya | Aura Voice Portal | 5.1 | - | All | All |
| Application | Avaya | Aura Voice Portal | 5.1 | sp1 | All | All |
| Application | Avaya | Iq | 5.0 | All | All | All |
| Application | Avaya | Iq | 5.1 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 10.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 10.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.10 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Vmware | Esx | 4.0 | All | All | All |
| Operating System | Vmware | Esx | 4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE request - kernel: xfs: stale data exposure | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| [PATCH] xfsqa: test open_by_handle() on unlinked and freed inode cluster | af854a3a-2127-422b-91ae-364da2661108 | oss.sgi.com | Broken Link |
| XFS Deleted Inode Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Third Party Advisory, VDB Entry |
| article.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | article.gmane.org | Broken Link |
| Bug 624923 – CVE-2010-2943 kernel: xfs: validate inode numbers in file handles correctly | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Ubuntu update for linux-source-2.6.15 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Re: [PATCH] xfsqa: test open_by_handle() on unlinked and freed inode clu | af854a3a-2127-422b-91ae-364da2661108 | oss.sgi.com | Broken Link |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| USN-1041-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| oss-security - CVE request - kernel: xfs: stale data exposure | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| VMSA-2011-0012.2 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Third Party Advisory |
| article.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | article.gmane.org | Broken Link |
| article.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | article.gmane.org | Broken Link |
| Ubuntu update for linux and linux-ec2 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| article.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | article.gmane.org | Broken Link |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| USN-1057-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Broken Link |
| ASA-2010-291 (RHSA-2010-0723) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.