CVE-2010-4073
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive...
- Published
- Nov 29, 2010
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Sep 5, 2011
Primary CVSS
nvd · CVSS 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:NLow · next 30 days
- Percentile
- 72.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c; and the (4) compat_sys_mq_open and (5) compat_sys_mq_getsetattr functions in ipc/compat_mq.c.
Sources
3- LinuxEelvationExploit
Linux Eelvation(持续更新)
- linux-kernel-exploitsExploit
linux-kernel-exploits Linux平台提权漏洞集合
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.