Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-3850Kernel vulnerability

15 documents8 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 75.09%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 30
Latest updateMay 13

Description

The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Also affects: Debian Linux 5.0, Ubuntu Linux 10.04, 10.10, 6.06, 8.04, 9.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-x5q7-74fg-9cp7: The ec_dev_ioctl function in net/econet/af_econet2022-05-13
CVEList
CVE-2010-3850: The ec_dev_ioctl function in net/econet/af_econet2010-12-30
Kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-2.62010-11-29
Kernel
econet: fix CVE-2010-38502010-11-24

💥Exploits & PoCs

2
Exploit-DB
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation2011-09-05
Exploit-DB
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation2010-12-07

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25

💬Community

1
Bugzilla
CVE-2010-3848 CVE-2010-3849 CVE-2010-3850 kernel: multiple vulnerabilities in Linux AF_ECONET2010-10-19
CVE-2010-3850 — Linux Kernel vulnerability | cvebase