CVE-2010-3477: Low severity Linux Linux kernel vulnerability
Last updated 24 July 2024
Other sources
The tcfactpolicedump function in net/sched/actpolice.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3477?
CVE-2010-3477 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2010-3477?
To fix CVE-2010-3477, upgrade the Linux kernel to version 2.6.36 or later.
Which Linux versions are affected by CVE-2010-3477?
CVE-2010-3477 affects the Linux kernel versions prior to 2.6.36.
Can CVE-2010-3477 be exploited remotely?
No, CVE-2010-3477 requires local access to exploit the vulnerability.
What is the impact of CVE-2010-3477?
The impact of CVE-2010-3477 allows local users to gain unauthorized access to sensitive information.