5.5
CVE-2010-2942
- EPSS 0.06%
- Published 21.09.2010 18:00:02
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
Data is provided by the National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 2.6.35.13
Linux ≫ Linux Kernel Version2.6.36 Update-
Linux ≫ Linux Kernel Version2.6.36 Updaterc1
Canonical ≫ Ubuntu Linux Version6.06
Canonical ≫ Ubuntu Linux Version8.04
Canonical ≫ Ubuntu Linux Version9.04
Canonical ≫ Ubuntu Linux Version9.10
Canonical ≫ Ubuntu Linux Version10.04 SwEdition-
Canonical ≫ Ubuntu Linux Version10.10
Suse ≫ Suse Linux Enterprise Desktop Version10 Updatesp3
Suse ≫ Suse Linux Enterprise Desktop Version11 Update-
Suse ≫ Suse Linux Enterprise Desktop Version11 Updatesp1
Suse ≫ Suse Linux Enterprise Server Version10 Updatesp3
Suse ≫ Suse Linux Enterprise Server Version11 Update-
Suse ≫ Suse Linux Enterprise Server Version11 Updatesp1
Avaya ≫ Aura Communication Manager Version5.2
Avaya ≫ Aura Presence Services Version6.0
Avaya ≫ Aura Presence Services Version6.1
Avaya ≫ Aura Presence Services Version6.1.1
Avaya ≫ Aura Session Manager Version1.1
Avaya ≫ Aura Session Manager Version5.2
Avaya ≫ Aura Session Manager Version6.0
Avaya ≫ Aura System Manager Version5.2
Avaya ≫ Aura System Manager Version6.0
Avaya ≫ Aura System Manager Version6.1
Avaya ≫ Aura System Manager Version6.1.1
Avaya ≫ Aura System Platform Version1.1
Avaya ≫ Aura System Platform Version6.0 Update-
Avaya ≫ Aura System Platform Version6.0 Updatesp1
Avaya ≫ Voice Portal Version5.0
Avaya ≫ Voice Portal Version5.1 Update-
Avaya ≫ Voice Portal Version5.1 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.188 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.