CVE-2010-3904
HIGH severity · CVSS 7.8 · CWE-1284 · actively exploited (CISA KEV)
7.8CVSS HIGH ● exploited
🔴 Actively exploited in the wild (CISA Known Exploited Vulnerabilities).
Added to KEV 2023-05-12. US federal agencies must patch by 2023-06-02.
Summary
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)2%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (4)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=799c10559d60f159ab2232203f222f18fa3c4a5f
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlAdvisory
- http://secunia.com/advisories/46397Advisory
- http://securitytracker.com/id?1024613Advisory
- http://www.kb.cert.org/vuls/id/362983Advisory
- http://packetstormsecurity.com/files/155751/vReliable-Datagram-Sockets-RDS-rds_page_copy_user-Privilege-Escalation.htmlAdvisory