CVE-2010-1636

The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
linuxlinux_kernel
2.6.29
linuxlinux_kernel
2.6.29.1
linuxlinux_kernel
2.6.29.2
linuxlinux_kernel
2.6.29.3
linuxlinux_kernel
2.6.29.4
linuxlinux_kernel
2.6.29.5
linuxlinux_kernel
2.6.29.6
linuxlinux_kernel
2.6.30
linuxlinux_kernel
2.6.30.1
linuxlinux_kernel
2.6.30.2
linuxlinux_kernel
2.6.30.3
linuxlinux_kernel
2.6.30.4
linuxlinux_kernel
2.6.30.5
linuxlinux_kernel
2.6.30.6
linuxlinux_kernel
2.6.30.7
linuxlinux_kernel
2.6.30.8
linuxlinux_kernel
2.6.30.9
linuxlinux_kernel
2.6.30.10
linuxlinux_kernel
2.6.31
linuxlinux_kernel
2.6.31.1
linuxlinux_kernel
2.6.31.2
linuxlinux_kernel
2.6.31.3
linuxlinux_kernel
2.6.31.4
linuxlinux_kernel
2.6.31.5
linuxlinux_kernel
2.6.31.6
linuxlinux_kernel
2.6.31.7
linuxlinux_kernel
2.6.31.8
linuxlinux_kernel
2.6.31.9
linuxlinux_kernel
2.6.31.10
linuxlinux_kernel
2.6.31.11
linuxlinux_kernel
2.6.31.12
linuxlinux_kernel
2.6.31.13
linuxlinux_kernel
2.6.32
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
lucid
Fixed 2.6.32-23.37
released
karmic
Fixed 2.6.31-22.61
released
jaunty
not-affected
hardy
not-affected
dapper
dne
linux-source-2.6.15
lucid
dne
karmic
dne
jaunty
dne
hardy
dne
dapper
not-affected