Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 2, 2023

CVE-2010-3904

High
EPSS 1.6%CISA KEV
Linux/Kernel

Description

Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

EPSS — Exploit Probability

1.6%

Higher than 81.4% of all CVEs

Required Action

https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html; https://nvd.nist.gov/vuln/detail/CVE-2010-3904

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
1.6%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 12, 2023

Added to KEV

May 12, 2023

Remediation Due

Jun 2, 2023

Affected Product

Linux

Kernel

View all Linux CVEs