Description
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
Affected products
- Canonical / Ubuntu Linux10.10 – 10.10
- Canonical / Ubuntu Linux6.06 – 6.06
- Canonical / Ubuntu Linux8.04 – 8.04
- Canonical / Ubuntu Linux9.04 – 9.04
- Canonical / Ubuntu Linux9.10 – 9.10
- Canonical / Ubuntu Linux10.04 – 10.04
- Debian / debian_linux5.0 – 5.0
- Linux / Linux kernel2.6.35
- SUSE / linux_enterprise_desktop10 – 10
- SUSE / linux_enterprise_server10 – 10
- SUSE / linux_enterprise_software_development_kit10 – 10
References
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0610.html
- MISChttp://archives.free.net.ph/message/20100616.135735.40f53a32.en.html
- MISChttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1817176a86352f65210139d4c794ad2d19fc6b63
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-1000-1
- MAILING_LISThttp://marc.info/?l=oss-security&m=127687486331790&w=2
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:198
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=605158
- MISChttp://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2011/0298
- MAILING_LISThttp://marc.info/?l=oss-security&m=127677135609357&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/43315
- MISChttp://archives.free.net.ph/message/20100616.130710.301704aa.en.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2010/dsa-2094
- VENDOR_ADVISORYhttp://www.vmware.com/security/advisories/VMSA-2011-0003.html
- MISChttp://www.securityfocus.com/bid/40920
- MISChttp://www.securityfocus.com/archive/1/516397/100/0/threaded