CVE-2010-4083Missing Initialization of Resource in Kernel

Severity
1.9LOWNVD
EPSS
0.1%
top 75.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 13

Description

The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT, or (4) SEM_STAT command in a semctl system call.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages6 packages

Also affects: Debian Linux 5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6r2h-x874-8mcw: The copy_semid_to_user function in ipc/sem2022-05-13
CVEList
CVE-2010-4083: The copy_semid_to_user function in ipc/sem2010-11-30

📋Vendor Advisories

10
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel (Maverick backport) vulnerabilities2011-08-09
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-02

💬Community

1
Bugzilla
CVE-2010-4083 kernel: ipc/sem.c: reading uninitialized stack memory2010-11-01
CVE-2010-4083 — Missing Initialization of Resource | cvebase