imPC@ndo IT

Tracker / CVE-2010-4347

CVE-2010-4347

Medium 6.9

The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.

Affected products and versions

linux linux_kernel · … → 2.6.36.2
opensuse opensuse
suse linux_enterprise_real_time_extension

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References