CVE-2010-4171

The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
systemtapsystemtap
1.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
systemtap
bookworm
4.8-2
fixed
bullseye
4.4-2
fixed
sid
5.1-4
fixed
trixie
5.1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
systemtap
dapper
dne
hardy
not-affected
karmic
not-affected
lucid
not-affected
maverick
Fixed 1.3-1ubuntu0.1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
systemtap
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-client
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-grapher
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-initscript
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-runtime
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-sdt-devel
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-server
RHEL 6
0:1.2-11.el6_0
fixed
systemtap-testsuite
RHEL 6
0:1.2-11.el6_0
fixed
References