EXPOSURES › CVE-2010-3904
CVE-2010-3904
HIGH ⌖ ON CISA KEV · EXPLOITEDLinux Kernel RDS protocol vulnerability allows local privilege escalation.
The Linux Kernel contains an improper input validation vulnerability in the RDS protocol, allowing local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. This vulnerability is actively exploited and poses a significant risk to systems running the Linux Kernel.
Shame score — The vulnerability is actively exploited and allows for local privilege escalation, which is a severe security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.