PT-2010-4846 · Linux+1 · Linux Kernel+1

Jeff Mahoney

·

Published

2010-09-21

·

Updated

2020-08-14

·

CVE-2010-3477

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.36-rc4
Description The issue is related to the tcf act police dump function in the network queueing functionality, which does not properly initialize certain structure members. This allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation.
Recommendations For Linux kernel versions prior to 2.6.36-rc4, update to version 2.6.36-rc4 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3477
DSA-2126-1
RHSA-2010:0779
RHSA-2010:0839
RHSA-2010_0779
RHSA-2010_0839
RHSA-2011:0007
RHSA-2011:0330
RHSA-2011_0007

Affected Products

Linux Kernel
Red Hat