CVE-2010-3904
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Activement exploitée
- Dans le catalogue CISA des vulnérabilités exploitées depuis le 12 mai 2023
- Les agences fédérales américaines doivent la corriger avant le 2 juin 2023 (BOD 22-01)
- Première attaque observée 4539 jours après la divulgation
The impacted product is end-of-life and should be disconnected if still in use.
Source : CISA KEV · 20 août 2026 12 mai 2023
Score CVSS7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HType de faiblesse (CWE)CWE-1284
Éditeursredhat, suse, linux, opensuse, canonical, vmware
Produits concernés
| Éditeurs | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 2.6.36 |
| opensuse | opensuse | 11.2 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 6.06 |
| redhat | enterprise linux | 5.0 |
| vmware | esxi | 3.5 |
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
