PT-2010-5158 · Linux+1 · Linux Kernel+1

Dan Rosenberg

·

Published

2010-10-25

·

Updated

2025-02-19

·

CVE-2010-3904

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 2.6.36
Description The issue is related to improper input validation in the Reliable Datagram Sockets (RDS) protocol implementation. Specifically, the rds page copy user function in net/rds/page.c does not properly validate addresses obtained from user space. This allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Recommendations For Linux Kernel versions prior to 2.6.36, update to version 2.6.36 or later to resolve the issue. As a temporary workaround, consider restricting the use of the sendmsg and recvmsg system calls to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2010-3904
RHSA-2010:0792
RHSA-2010:0842
RHSA-2010_0792
RHSA-2010_0842

Affected Products

Linux Kernel
Red Hat