Unrated severityNVD Advisory· Published Sep 3, 2010· Updated Apr 29, 2026
CVE-2010-2240
CVE-2010-2240
Description
The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.
Affected products
24cpe:2.3:o:linux:linux_kernel:2.6.32.17:*:*:*:*:*:*:*+ 23 more
- cpe:2.3:o:linux:linux_kernel:2.6.32.17:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.18:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34.1:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34.2:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=2.6.27.51
- cpe:2.3:o:linux:linux_kernel:2.6.32:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.1:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.2:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.3:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.4:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.7:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.8:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.9:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.10:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.11:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.12:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.13:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.14:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.15:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32.16:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34.3:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.35.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- www.invisiblethingslab.com/resources/misc-2010/xorg-large-memory-attacks.pdfnvdExploit
- lists.vmware.com/pipermail/security-announce/2011/000133.htmlnvd
- securitytracker.com/idnvd
- www.debian.org/security/2010/dsa-2094nvd
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.52nvd
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.19nvd
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34.4nvd
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35.2nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2010-0660.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0670.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0882.htmlnvd
- www.securityfocus.com/archive/1/517739/100/0/threadednvd
- www.vmware.com/security/advisories/VMSA-2011-0007.htmlnvd
- www.vmware.com/security/advisories/VMSA-2011-0009.htmlnvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13247nvd
- rhn.redhat.com/errata/RHSA-2010-0661.htmlnvd
News mentions
0No linked articles in our index yet.