Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-3849NULL Pointer Dereference in Kernel

Severity
4.7MEDIUMNVD
EPSS
0.2%
top 60.34%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 30
Latest updateMay 13

Description

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages5 packages

Also affects: Debian Linux 5.0, Ubuntu Linux 10.04, 10.10, 6.06, 8.04, 9.10

Patches

🔴Vulnerability Details

6
GHSA
GHSA-23jc-mx6c-hh36: The econet_sendmsg function in net/econet/af_econet2022-05-13
CVEList
CVE-2010-3849: The econet_sendmsg function in net/econet/af_econet2010-12-30
Kernel
do_exit(): make sure that we run with get_fs() == USER_DS2010-12-02
Kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-2.62010-11-29
Kernel
econet: disallow NULL remote addr for sendmsg(), fixes CVE-2010-38492010-11-24

💥Exploits & PoCs

2
Exploit-DB
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation2010-12-07
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'Snmp.exe' CGI Buffer Overflow (Metasploit)2010-11-11

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25

💬Community

2
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path2010-12-03
Bugzilla
CVE-2010-3848 CVE-2010-3849 CVE-2010-3850 kernel: multiple vulnerabilities in Linux AF_ECONET2010-10-19
CVE-2010-3849 — NULL Pointer Dereference in Kernel | cvebase