# Kernel vulnerability

**URL:** <https://forums.suse.com/t/kernel-vulnerability/21829>\
**Category:** SLES Configure-Administer\
**Created:** [October 4, 2011, 7:36pm UTC](https://forums.suse.com/t/kernel-vulnerability/21829 "2011-10-04T19:36:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![System1](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@System1](https://forums.suse.com/u/System1)\
**Post date:** [October 4, 2011, 7:36pm UTC](https://forums.suse.com/t/kernel-vulnerability/21829/1 "2011-10-04T19:36:02Z")

</div>

Any suggestions for dealing with CVE-2010-3849, since no version of SLES  
has the minimum kernel version to fix this problem? Also, we’re running  
OES, so we need a fix for SLES 10. From the security scan:

Multiple vulnerabilities exists in Linux Kernel caused by:-

1. The econet\_sendmsg function in net/econet/af\_econet.c in the  
Linux kernel and
2. The ec\_dev\_ioctl function in net/econet/af\_econet.c in the Linux  
kernel

The vulnerabilities are reported in all the Linux Kernel versions  
before 2.6.36.2.  
IMPACT:  
Successful exploitation allows local users to bypass intended  
access restrictions and cause a denial of service.  
SOLUTION:  
Update to version 2.6.36.2 to resolve the issue.

‘CVE - CVE-2010-3849 (under review)’  
([http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3849](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3849))

Aw, nuts, I just reread it and see the part about local users, which we  
don’t have other than admins. I guess this isn’t really an issue, but  
I’ll post anyway for anyone who does have local users and needs to  
address it.

## – zenking

zenking’s Profile: [http://forums.novell.com/member.php?userid=2813](http://forums.novell.com/member.php?userid=2813)  
View this thread: [http://forums.novell.com/showthread.php?t=445962](http://forums.novell.com/showthread.php?t=445962)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [October 4, 2011, 8:00pm UTC](https://forums.suse.com/t/kernel-vulnerability/21829/2 "2011-10-04T20:00:20Z")

</div>

On Tue, 04 Oct 2011 16:36:02 GMT  
zenking [zenking@no-mx.forums.novell.com](mailto:zenking@no-mx.forums.novell.com) wrote:  
[color=blue]

> Any suggestions for dealing with CVE-2010-3849, since no version of  
> SLES has the minimum kernel version to fix this problem? Also, we’re  
> running OES, so we need a fix for SLES 10. From the security scan:
> 
> Multiple vulnerabilities exists in Linux Kernel caused by:-
> 
> 1. The econet\_sendmsg function in net/econet/af\_econet.c in the  
> Linux kernel and
> 2. The ec\_dev\_ioctl function in net/econet/af\_econet.c in the Linux  
> kernel
> 
> The vulnerabilities are reported in all the Linux Kernel versions  
> before 2.6.36.2.  
> IMPACT:  
> Successful exploitation allows local users to bypass intended  
> access restrictions and cause a denial of service.  
> SOLUTION:  
> Update to version 2.6.36.2 to resolve the issue.
> 
> ‘CVE - CVE-2010-3849 (under review)’  
> ([http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3849](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3849))
> 
> Aw, nuts, I just reread it and see the part about local users, which  
> we don’t have other than admins. I guess this isn’t really an issue,  
> but I’ll post anyway for anyone who does have local users and needs to  
> address it.
> 
> [/color]  
> Hi  
> Fixed a long time ago;  
> [http://support.novell.com/security/cve/CVE-2010-3849.html](http://support.novell.com/security/cve/CVE-2010-3849.html)

Security issues are backported so you need to check the changelogs.

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.7-desktop  
up 8 days 3:45, 3 users, load average: 0.19, 0.22, 0.20  
GPU GeForce 8600 GTS Silent - Driver Version: 280.13

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [October 4, 2011, 9:36pm UTC](https://forums.suse.com/t/kernel-vulnerability/21829/3 "2011-10-04T21:36:02Z")

</div>

Thanks, Malcolm.

## – zenking

zenking’s Profile: [http://forums.novell.com/member.php?userid=2813](http://forums.novell.com/member.php?userid=2813)  
View this thread: [http://forums.novell.com/showthread.php?t=445962](http://forums.novell.com/showthread.php?t=445962)
