cbcvebase.
CVE-2010-3859
published 2010-12-29

CVE-2010-3859: Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg…

PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.40%
32.5th percentile
Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
linuxlinux_kernel< 2.6.36.22.6.36.2
vmwarevmware_esxi
vmwarevmware_workstation
vmwarevsphere

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu7.2HIGH
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.