CVE-2010-3876Missing Initialization of Resource in Kernel

Severity
1.9LOWNVD
EPSS
0.1%
top 82.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 13

Description

net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages6 packages

Also affects: Debian Linux 5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v3hw-wjfp-h8fp: net/packet/af_packet2022-05-13
CVEList
CVE-2010-3876: net/packet/af_packet2011-01-03

💥Exploits & PoCs

1
Exploit-DB
SmarterMail 7.1.3876 - Directory Traversal2010-09-19

📋Vendor Advisories

11
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-02

💬Community

1
Bugzilla
CVE-2010-3876 kernel: net/packet/af_packet.c: reading uninitialized stack memory2010-11-04
CVE-2010-3876 — Missing Initialization of Resource | cvebase