CVE-2010-3904
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Aktiv ausgenutzt
- Seit dem 12. Mai 2023 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 2. Juni 2023 beheben (BOD 22-01)
- Erster Angriff 4539 Tage nach der Veröffentlichung beobachtet
The impacted product is end-of-life and should be disconnected if still in use.
Quelle: CISA KEV · 20. Aug. 2026 12. Mai 2023
CVSS-Score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-1284
Herstellerredhat, suse, linux, opensuse, canonical, vmware
Betroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 2.6.36 |
| opensuse | opensuse | 11.2 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 6.06 |
| redhat | enterprise linux | 5.0 |
| vmware | esxi | 3.5 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
