← All CVEs

CVE-2010-3904

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2023-05-12Remediation due 2023-06-02

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

7.8
CVSS
14.5%
EPSS (exploit prob.)
96th
EPSS percentile
2010-12-06
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-1284

Affected products

VendorProductAffected versions
linuxlinux_kernel< 2.6.36
opensuseopensuse11.2
opensuseopensuse11.3
suselinux_enterprise_desktop11
suselinux_enterprise_real_time_extension11
suselinux_enterprise_server11
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux9.04
canonicalubuntu_linux9.10
canonicalubuntu_linux10.04
canonicalubuntu_linux10.10
redhatenterprise_linux5.0
redhatenterprise_linux6.0
vmwareesxi3.5
vmwareesxi4.0
vmwareesxi4.1
vmwareesxi5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-3904