CVE-2010-3904
Linux Kernel Improper Input Validation Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.8
- EPSS
- 11.2% 백분위 95.4% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.06.02
- 공개일
- 2010.12.07
CISA KEV에 등록된 실제 악용 확인 취약점
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
공급사 Linux
제품 Kernel
영향 버전 n/a, < 2.6.36, 11.2, 11.3, 11, 6.06, 8.04, 9.04, 9.10, 10.04, 10.10, 5.0, 6.0, 3.5, 4.0, 4.1
수정 버전 2.6.36
The impacted product is end-of-life and should be disconnected if still in use.
조치 기한: 2023.06.02CVSS 벡터 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-1284, CWE-20
KEV 등록일 2023.05.12
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html; https://nvd.nist.gov/vuln/detail/CVE-2010-3904
EPSS 데이터 기준일 2026.06.27