Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92x6-4gf8-7hcj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

EPSS

Процентиль: 83%
0.02116
Низкий

7.8 High

CVSS3

Дефекты

CWE-1284
CWE-20

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 14 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

redhat
больше 14 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

CVSS3: 7.8
nvd
больше 14 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

CVSS3: 7.8
debian
больше 14 лет назад

The rds_page_copy_user function in net/rds/page.c in the Reliable Data ...

oracle-oval
больше 14 лет назад

ELSA-2010-0792: kernel security update (IMPORTANT)

EPSS

Процентиль: 83%
0.02116
Низкий

7.8 High

CVSS3

Дефекты

CWE-1284
CWE-20