CVE-2010-2955

EUVD-2010-2959
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.36
linuxlinux_kernel
2.6.36
linuxlinux_kernel
2.6.36:rc1
linuxlinux_kernel
2.6.36:rc2
opensuseopensuse
11.1
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
hardy
not-affected
jaunty
Fixed 2.6.28-19.66
released
karmic
Fixed 2.6.31-22.67
released
lucid
Fixed 2.6.32-26.47
released
maverick
Fixed 2.6.35-22.34
released
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
linux-armadaxp
hardy
dne
lucid
dne
natty
dne
oneiric
dne
precise
not-affected
quantal
not-affected
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-backports-modules-2.6.24
dapper
dne
hardy
ignored
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-backports-modules-2.6.28
dapper
dne
hardy
dne
jaunty
ignored
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-backports-modules-2.6.32
dapper
dne
hardy
dne
jaunty
dne
karmic
dne
lucid
ignored
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-ec2
dapper
dne
hardy
dne
jaunty
dne
karmic
Fixed 2.6.31-307.21
released
lucid
Fixed 2.6.32-310.21
released
maverick
ignored
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-flo
lucid
dne
precise
dne
quantal
dne
saucy
dne
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
linux-fsl-imx51
dapper
dne
hardy
dne
karmic
Fixed 2.6.31-112.30
released
lucid
Fixed 2.6.31-608.22
released
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-goldfish
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
linux-grouper
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
not-affected
vivid
dne
wily
dne
linux-lts-backport-maverick
dapper
dne
hardy
dne
jaunty
dne
karmic
dne
lucid
Fixed 2.6.35-22.34~lucid1
released
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-backport-natty
hardy
dne
lucid
not-affected
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-backport-oneiric
hardy
dne
lucid
not-affected
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-quantal
hardy
dne
lucid
dne
oneiric
dne
precise
not-affected
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-raring
hardy
dne
lucid
dne
oneiric
dne
precise
not-affected
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-saucy
lucid
dne
precise
not-affected
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-trusty
lucid
dne
precise
not-affected
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-utopic
lucid
dne
precise
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-lts-vivid
lucid
dne
precise
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-maguro
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-mako
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
linux-manta
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
linux-mvl-dove
dapper
dne
hardy
dne
karmic
ignored
lucid
Fixed 2.6.32-213.29
released
maverick
Fixed 2.6.32-414.30
released
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-raspi2
precise
dne
trusty
dne
vivid
dne
wily
not-affected
linux-source-2.6.15
dapper
not-affected
hardy
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
linux-ti-omap4
dapper
dne
hardy
dne
karmic
dne
lucid
dne
maverick
Fixed 2.6.35-903.22
released
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
dne
vivid
dne
wily
dne
References