Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2010-4157

MEDIUM severity · CVSS 6.2 · Integer overflow
6.2CVSS MEDIUM

Summary

Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.

Impact & exploitability

Attack vectorLocal
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)1%

AV:L/AC:H/Au:N/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.