CVE-2010-3904
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 12 mag 2023
- Le agenzie federali statunitensi devono correggerla entro il 2 giu 2023 (direttiva BOD 22-01)
- Primo attacco osservato 4539 giorni dopo la divulgazione
The impacted product is end-of-life and should be disconnected if still in use.
Fonte: CISA KEV · 20 ago 2026 12 mag 2023
Punteggio CVSS7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HTipo di debolezza (CWE)CWE-1284
Vendorredhat, suse, linux, opensuse, canonical, vmware
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 2.6.36 |
| opensuse | opensuse | 11.2 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 6.06 |
| redhat | enterprise linux | 5.0 |
| vmware | esxi | 3.5 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
