Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92x6-4gf8-7hcj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

EPSS

Процентиль: 82%
0.01698
Низкий

7.8 High

CVSS3

Дефекты

CWE-1284
CWE-20

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 15 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

redhat
почти 15 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

CVSS3: 7.8
nvd
почти 15 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

CVSS3: 7.8
debian
почти 15 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Data ...

oracle-oval
почти 15 лет назад

ELSA-2010-0792: kernel security update (IMPORTANT)

EPSS

Процентиль: 82%
0.01698
Низкий

7.8 High

CVSS3

Дефекты

CWE-1284
CWE-20