CVE-2010-3876
LOW severity · CVSS 1.9 · CWE-909
1.9CVSS LOW
Summary
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
Impact & exploitability
Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%
AV:L/AC:M/Au:N/C:P/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://marc.info/?l=linux-netdev&m=128854507220908&w=2 ↗
Additional information
- NVD record
- http://marc.info/?l=linux-netdev&m=128854507220908&w=2Patch
- http://openwall.com/lists/oss-security/2010/11/02/10Patch
- http://openwall.com/lists/oss-security/2010/11/02/7Patch
- http://openwall.com/lists/oss-security/2010/11/02/9Patch
- http://openwall.com/lists/oss-security/2010/11/04/5Patch
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67286640f638f5ad41a946b9a3dc75327950248f
- http://openwall.com/lists/oss-security/2010/11/02/12Advisory
- http://secunia.com/advisories/42789Advisory