Skip to content
COOEY

EXPOSURES › CVE-2010-3904

CVE-2010-3904

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-3904 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Linux Kernel RDS protocol vulnerability allows local privilege escalation.

The Linux Kernel contains an improper input validation vulnerability in the RDS protocol, allowing local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. This vulnerability is actively exploited and poses a significant risk to systems running the Linux Kernel.

Shame score — The vulnerability is actively exploited and allows for local privilege escalation, which is a severe security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.