CVE-2010-3865

Severity
7.2HIGH
EPSS
0.1%
top 78.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateMay 13

Description

Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which triggers a buffer overflow.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qm3q-m933-m78g: Integer overflow in the rds_rdma_pages function in net/rds/rdma2022-05-13
CVEList
CVE-2010-3865: Integer overflow in the rds_rdma_pages function in net/rds/rdma2011-01-11

📋Vendor Advisories

11
Microsoft
CVE-2010-3865: NIST NVD Details: https://nvd2020-09-08
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25

💬Community

1
Bugzilla
CVE-2010-3865 kernel: iovec integer overflow in net/rds/rdma.c2010-10-28
CVE-2010-3865 (HIGH CVSS 7.2) | Integer overflow in the rds_rdma_pa | cvebase.io