CVE-2010-4072 — Sensitive Information Exposure in Kernel
Severity
1.9LOWNVD
EPSS
0.1%
top 78.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateMay 13
Description
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
CVSS vector
AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9
Affected Packages6 packages
Also affects: Debian Linux 5.0, Ubuntu Linux 10.04, 10.10, 6.06, 9.10