Junglewise Threat Intelligence

CVE-2010-3904: Linux Kernel Improper Input Validation Vulnerability

CVE-2010-3904 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-05-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The rds_page_copy_user function in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel fails to properly validate user-space addresses. Local attackers can exploit this flaw via crafted sendmsg and recvmsg system calls to escalate privileges.

Affected products

  • Linux Linux Kernel before 2.6.36

Timeline

  • 2010-10-19: disclosed: Initial advisory and exploit details published.
  • 2010-10-20: patched: Linux kernel 2.6.36 released containing the fix.
  • 2023-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats