peter bassill · operator
$ cve CVE-2010-4165 JSON

CVE-2010-4165 EXPLOIT

4.9
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 73)

Patch early

A public exploit exists.

Description

The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.

Scoring

CVSS4.9 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS1.48% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-369
On CISA KEVno
Public exploityes
Published2010-11-22
Last modified2026-06-16

Affected (5)

VendorProduct
linuxlinux kernel
opensuseopensuse
suselinux enterprise desktop
suselinux enterprise real time extension
suselinux enterprise server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD