7.8

CVE-2010-3904

Warnung
Medienbericht
Exploit
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 2.6.36
Opensuse ≫ Opensuse Version 11.2
Opensuse ≫ Opensuse Version 11.3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp1
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update sp1
Canonical ≫ Ubuntu Linux Version 6.06
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 9.04
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 10.10
Redhat ≫ Enterprise Linux Version 5.0
Redhat ≫ Enterprise Linux Version 6.0
VMware ≫ ESXi Version 3.5
VMware ≫ ESXi Version 4.0
VMware ≫ ESXi Version 4.1
VMware ≫ ESXi Version 5.0

12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Improper Input Validation Vulnerability

Schwachstelle

Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

Beschreibung

The impacted product is end-of-life and should be disconnected if still in use.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.16% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.08.2026 11:01
http://secunia.com/advisories/46397
Third Party Advisory
Broken Link
http://www.securityfocus.com/archive/1/520102/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-1000-1
Third Party Advisory
http://www.vupen.com/english/advisories/2011/0298
Third Party Advisory
Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0842.html
Third Party Advisory
Broken Link
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.html
Third Party Advisory
Mailing List
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=799c10559d60f159ab2232203f222f18fa3c4a5f
Broken Link
http://packetstormsecurity.com/files/155751/vReliable-Datagram-Sockets-RDS-rds_page_copy_user-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://securitytracker.com/id?1024613
Third Party Advisory
Broken Link
VDB Entry
http://www.kb.cert.org/vuls/id/362983
Third Party Advisory
US Government Resource
http://www.redhat.com/support/errata/RHSA-2010-0792.html
Third Party Advisory
Broken Link
http://www.vsecurity.com/download/tools/linux-rds-exploit.c
Broken Link
http://www.vsecurity.com/resources/advisory/20101019-1/
Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=642896
Patch
Third Party Advisory
Issue Tracking
https://www.exploit-db.com/exploits/44677/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3904
US Government Resource