CVE-2010-4258 EXPLOIT
6.2
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
Scoring
| CVSS | 6.2 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
| EPSS | 2.66% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-12-30 |
| Last modified | 2026-06-16 |
Affected (7)
| Vendor | Product |
|---|---|
| fedoraproject | fedora |
| linux | linux kernel |
| opensuse | opensuse |
| suse | linux enterprise desktop |
| suse | linux enterprise real time extension |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation | 2010-12-07 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0086.html
- http://blog.nelhage.com/2010/12/cve-2010-4258-from-dos-to-privesc/
- http://code.google.com/p/chromium-os/issues/detail?id=10234
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=33dd94ae1ccbfb7bf0fb6c692bc3d1c4269e6177
- http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html
- http://marc.info/?l=linux-kernel&m=129117048916957&w=2
- http://openwall.com/lists/oss-security/2010/12/02/2
- http://openwall.com/lists/oss-security/2010/12/02/3
- http://openwall.com/lists/oss-security/2010/12/02/4
- http://openwall.com/lists/oss-security/2010/12/02/7
- http://openwall.com/lists/oss-security/2010/12/08/4
- http://openwall.com/lists/oss-security/2010/12/08/5
- http://openwall.com/lists/oss-security/2010/12/08/9
→ the Explorer · watch your stack · NVD