CVE-2010-4074

The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.36
linuxlinux_kernel
2.6.36
linuxlinux_kernel
2.6.36:rc1
linuxlinux_kernel
2.6.36:rc2
linuxlinux_kernel
2.6.36:rc3
linuxlinux_kernel
2.6.36:rc4
debiandebian_linux
5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
maverick
not-affected
lucid
not-affected
karmic
Fixed 2.6.31-22.73
released
hardy
Fixed 2.6.24-28.86
released
dapper
dne
linux-ec2
maverick
ignored
lucid
not-affected
karmic
Fixed 2.6.31-307.27
released
hardy
dne
dapper
dne
linux-fsl-imx51
maverick
dne
lucid
Fixed 2.6.31-608.22
released
karmic
Fixed 2.6.31-112.30
released
hardy
dne
dapper
dne
linux-lts-backport-maverick
maverick
dne
lucid
not-affected
karmic
dne
hardy
dne
dapper
dne
linux-mvl-dove
maverick
not-affected
lucid
not-affected
karmic
ignored
hardy
dne
dapper
dne
linux-source-2.6.15
maverick
dne
lucid
dne
karmic
dne
hardy
dne
dapper
not-affected
linux-ti-omap4
maverick
not-affected
lucid
dne
karmic
dne
hardy
dne
dapper
dne