CVE-2010-3861Sensitive Information Exposure in Kernel

Severity
2.1LOWNVD
CNA7.2
EPSS
0.1%
top 83.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 13

Description

The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Also affects: Ubuntu Linux 10.04, 10.10, 9.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fp8j-xh66-8w79: The ethtool_get_rxnfc function in net/core/ethtool2022-05-13
CVEList
CVE-2010-3861: The ethtool_get_rxnfc function in net/core/ethtool2010-12-10

💥Exploits & PoCs

1
Exploit-DB
SafeNet SoftRemote - GROUPNAME Buffer Overflow (Metasploit)2010-11-11

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25

💬Community

1
Bugzilla
CVE-2010-3861 kernel: heap contents leak from ETHTOOL_GRXCLSRLALL2010-10-26
CVE-2010-3861 — Sensitive Information Exposure | cvebase