CVE-2010-1146

The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by deleting a file under .reiserfs_priv/xattrs/.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.33.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
hardy
Fixed 2.6.24-28.70
released
intrepid
ignored
jaunty
Fixed 2.6.28-19.61
released
karmic
Fixed 2.6.31-22.60
released
lucid
Fixed 2.6.32-22.35
released
linux-source-2.6.15
dapper
Fixed 2.6.15-55.84
released
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-default
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-docs
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-macros
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-obs-build
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-source
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-syms
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
kernel-vanilla-base
suse enterprise desktop 15
4.12.14-23.1
fixed
suse enterprise sap 15
4.12.14-23.1
fixed
suse enterprise server 15
4.12.14-23.1
fixed
Common Weakness Enumeration