CVE-2010-3904
Linux Kernel Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 14.58% probability · 96th percentile
- CISA KEV
- Listed 12 May 2023 · due 2 June 2023
- Weakness
- CWE-1284
- Affected
- linux/linux kernel · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise real time extension · suse/linux enterprise server · canonical/ubuntu linux · redhat/enterprise linux · vmware/esxi
- Source
- security@ubuntu.com
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html; https://nvd.nist.gov/vuln/detail/CVE-2010-3904
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=799c10559d60f159ab2232203f222f18fa3c4a5fBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155751/vReliable-Datagram-Sockets-RDS-rds_page_copy_user-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/46397Broken Link, Third Party Advisory
- http://securitytracker.com/id?1024613Broken Link, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/362983Third Party Advisory, US Government Resource
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36Broken Link
- http://www.redhat.com/support/errata/RHSA-2010-0792.htmlBroken Link, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.htmlBroken Link, Third Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1000-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- http://www.vsecurity.com/download/tools/linux-rds-exploit.cBroken Link
- http://www.vsecurity.com/resources/advisory/20101019-1/Broken Link
- http://www.vupen.com/english/advisories/2011/0298Broken Link, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=642896Issue Tracking, Patch, Third Party Advisory
- https://www.exploit-db.com/exploits/44677/Exploit, Third Party Advisory, VDB Entry
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=799c10559d60f159ab2232203f222f18fa3c4a5fBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155751/vReliable-Datagram-Sockets-RDS-rds_page_copy_user-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/46397Broken Link, Third Party Advisory
- http://securitytracker.com/id?1024613Broken Link, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/362983Third Party Advisory, US Government Resource
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36Broken Link
- http://www.redhat.com/support/errata/RHSA-2010-0792.htmlBroken Link, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.htmlBroken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.