CVE-2010-3880

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 2
Advisories 28

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

Weaknesses
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2010-12-10 19:00:04
(13 years ago)
Updated Date
2023-02-13 04:27:27
(19 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 2.6.37 version cpe:2.3:o:linux:linux_kernel < 2.6.37
  Linux Kernel 2.6.37 cpe:2.3:o:linux:linux_kernel:2.6.37:-
  Linux Kernel 2.6.37 Rc1 cpe:2.3:o:linux:linux_kernel:2.6.37:rc1

Configuration #2

    CPE23 From Up To
  Debian Linux 5.0 cpe:2.3:o:debian:debian_linux:5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...