CVE-2010-3904
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Explotada activamente
- En el catálogo CISA de vulnerabilidades explotadas desde el 12 may 2023
- Las agencias federales de EE. UU. deben corregirla antes del 2 jun 2023 (BOD 22-01)
- Primer ataque observado 4539 días después de la divulgación
The impacted product is end-of-life and should be disconnected if still in use.
Fuente: CISA KEV · 20 ago 2026 12 may 2023
Puntuación CVSS7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HTipo de debilidad (CWE)CWE-1284
Fabricantesredhat, suse, linux, opensuse, canonical, vmware
Productos afectados
| Fabricantes | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 2.6.36 |
| opensuse | opensuse | 11.2 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 6.06 |
| redhat | enterprise linux | 5.0 |
| vmware | esxi | 3.5 |
Artículos relacionados
This product uses the NVD API but is not endorsed or certified by the NVD.
