CVE-2010-2525
Publication date 16 May 2012
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system.
From the Ubuntu Security Team
Dan Rosenberg discovered a flaw in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Fixed 2.6.35-22.35
|
|
10.04 LTS lucid |
Fixed 2.6.32-25.43
|
|
9.10 karmic |
Fixed 2.6.31-22.67
|
|
9.04 jaunty |
Fixed 2.6.28-19.66
|
|
8.04 LTS hardy |
Fixed 2.6.24-28.80
|
|
linux-armadaxp | 12.04 LTS precise |
Not affected
|
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
linux-ec2 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid |
Fixed 2.6.32-309.17
|
|
9.10 karmic |
Fixed 2.6.31-307.21
|
|
8.04 LTS hardy | Not in release | |
linux-fsl-imx51 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release | |
linux-linaro-omap | 12.04 LTS precise | Ignored end of life |
11.10 oneiric | Ignored end of life | |
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
linux-linaro-shared | 12.04 LTS precise | Ignored end of life |
11.10 oneiric | Ignored end of life | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
linux-linaro-vexpress | 12.04 LTS precise | Ignored end of life |
11.10 oneiric | Ignored end of life | |
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
linux-lts-backport-maverick | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release | |
linux-lts-backport-natty | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid |
Not affected
|
|
8.04 LTS hardy | Not in release | |
linux-lts-backport-oneiric | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid |
Not affected
|
|
8.04 LTS hardy | Not in release | |
linux-mvl-dove | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release | |
linux-qcm-msm | 12.04 LTS precise | Ignored end of life |
11.10 oneiric | Ignored end of life | |
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release | |
linux-source-2.6.15 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper |
Fixed 2.6.15-55.89
|
|
linux-ti-omap4 | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Not affected
|
|
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Notes
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-1000-1
- Linux kernel vulnerabilities
- 19 October 2010