CVE-2010-3881

Severity
2.1LOW
EPSS
0.1%
top 77.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateMay 13

Description

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7ggg-v588-6483: arch/x86/kvm/x862022-05-13
CVEList
CVE-2010-3881: arch/x86/kvm/x862010-12-23

📋Vendor Advisories

6
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (EC2)2011-07-13
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-02-01

💬Community

1
Bugzilla
CVE-2010-3881 kvm: arch/x86/kvm/x86.c: reading uninitialized stack memory2010-11-04
CVE-2010-3881 (LOW CVSS 2.1) | arch/x86/kvm/x86.c in the Linux ker | cvebase.io