PT-2010-5158 · Linux+1 · Linux Kernel+1

·

CVE-2010-3904

·

Publicado

2010-10-25

·

Atualizado

2025-02-19

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 2.6.36
Description The issue is related to improper input validation in the Reliable Datagram Sockets (RDS) protocol implementation. Specifically, the rds page copy user function in net/rds/page.c does not properly validate addresses obtained from user space. This allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Recommendations For Linux Kernel versions prior to 2.6.36, update to version 2.6.36 or later to resolve the issue. As a temporary workaround, consider restricting the use of the sendmsg and recvmsg system calls to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3904
RHSA-2010:0792
RHSA-2010:0842
RHSA-2010_0792
RHSA-2010_0842

Produtos afetados

Linux Kernel
Red Hat