CVE-2010-4655Improper Initialization in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 83.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 13

Description

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDlinux/linux_kernel< 2.6.36
NVDvmware/esx4.0, 4.1+1

Also affects: Ubuntu Linux 8.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c9rp-95rg-526v: net/core/ethtool2022-05-13
CVEList
CVE-2010-4655: net/core/ethtool2011-07-18

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-09-13
Ubuntu
Linux kernel vulnerabilities (i.MX51)2011-07-06
Ubuntu
Linux kernel vulnerabilities2011-06-09
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03

💬Community

1
Bugzilla
CVE-2010-4655 kernel: heap contents leak for CAP_NET_ADMIN via ethtool ioctl2011-01-25
CVE-2010-4655 — Improper Initialization in Linux Kernel | cvebase