cbcvebase.
CVE-2010-3861
published 2010-12-10

CVE-2010-3861: The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local…

low2.1CVSS 3.1
AVLACLAuNCPINAN
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.

Affected

9 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
linuxlinux_kernel< 2.6.362.6.36
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_real_time_extension
suselinux_enterprise_server