CVE-2010-1083

Publication date 6 April 2010

Last updated 24 July 2024


Ubuntu priority

The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).

Status

Package Ubuntu Release Status
linux 10.04 LTS lucid
Fixed 2.6.32-22.35
9.10 karmic
Fixed 2.6.31-22.60
9.04 jaunty
Fixed 2.6.28-19.61
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy
Fixed 2.6.24-28.70
6.06 LTS dapper Not in release
linux-source-2.6.15 10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper
Fixed 2.6.15-55.84

References

Related Ubuntu Security Notices (USN)

    • USN-947-1
    • Linux kernel vulnerabilities
    • 3 June 2010

Other references