CVE-2010-3861
10.12.2010, 19:00
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.36 |
opensuse | opensuse | 11.2 |
opensuse | opensuse | 11.3 |
canonical | ubuntu_linux | 9.10 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 10.10 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||||
linux-ec2 |
| ||||||||||||
linux-fsl-imx51 |
| ||||||||||||
linux-lts-backport-maverick |
| ||||||||||||
linux-mvl-dove |
| ||||||||||||
linux-source-2.6.15 |
| ||||||||||||
linux-ti-omap4 |
|
Common Weakness Enumeration
References