CVE-2010-1636

EUVD-2010-1657
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
2.6.29
linuxlinux_kernel
2.6.29.1
linuxlinux_kernel
2.6.29.2
linuxlinux_kernel
2.6.29.3
linuxlinux_kernel
2.6.29.4
linuxlinux_kernel
2.6.29.5
linuxlinux_kernel
2.6.29.6
linuxlinux_kernel
2.6.30
linuxlinux_kernel
2.6.30.1
linuxlinux_kernel
2.6.30.2
linuxlinux_kernel
2.6.30.3
linuxlinux_kernel
2.6.30.4
linuxlinux_kernel
2.6.30.5
linuxlinux_kernel
2.6.30.6
linuxlinux_kernel
2.6.30.7
linuxlinux_kernel
2.6.30.8
linuxlinux_kernel
2.6.30.9
linuxlinux_kernel
2.6.30.10
linuxlinux_kernel
2.6.31
linuxlinux_kernel
2.6.31.1
linuxlinux_kernel
2.6.31.2
linuxlinux_kernel
2.6.31.3
linuxlinux_kernel
2.6.31.4
linuxlinux_kernel
2.6.31.5
linuxlinux_kernel
2.6.31.6
linuxlinux_kernel
2.6.31.7
linuxlinux_kernel
2.6.31.8
linuxlinux_kernel
2.6.31.9
linuxlinux_kernel
2.6.31.10
linuxlinux_kernel
2.6.31.11
linuxlinux_kernel
2.6.31.12
linuxlinux_kernel
2.6.31.13
linuxlinux_kernel
2.6.32
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
hardy
not-affected
jaunty
not-affected
karmic
Fixed 2.6.31-22.61
released
lucid
Fixed 2.6.32-23.37
released
linux-source-2.6.15
dapper
not-affected
hardy
dne
jaunty
dne
karmic
dne
lucid
dne