CVE-2010-4243
Summary
| CVE | CVE-2010-4243 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-22 22:00:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | VDB Entry |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Broken Link |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| 625688 – (CVE-2010-4243) CVE-2010-4243 kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | grsecurity.net | Broken Link |
| Linux Kernel 'setup_arg_pages()' Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| oss-security - CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Third Party Advisory |
| LKML: KOSAKI Motohiro: Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Mailing List, Patch, Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| VMSA-2011-0012.2 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Third Party Advisory |
| LKML: Roland McGrath: Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Mailing List, Patch, Third Party Advisory |
| oss-security - Re: CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Third Party Advisory |
| LKML: Solar Designer: Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Mailing List, Third Party Advisory |
| LKML: Kees Cook: [PATCH] exec argument expansion can inappropriately trigger OOM-killer | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Mailing List, Patch, Third Party Advisory |
| Red Hat update for kernel - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| linux.derkeiler.com/Mailing-Lists/Kernel/2010-11/msg13278.html | af854a3a-2127-422b-91ae-364da2661108 | linux.derkeiler.com | Broken Link |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.