CVE-2010-4158: Infoleak
Description of problem: The "mem" array used as scratch space for socket filters is not initialized, allowing unprivileged users to leak kernel stack bytes.
http://www.spinics.net/lists/netdev/msg146361.html http://lists.grok.org.uk/pipermail/full-disclosure/2010-November/077321.html
Acknowledgements:
Red Hat would like to thank Dan Rosenberg for reporting this issue.
Other sources
The skrunfilter function in net/core/filter.c in the Linux kernel be ...
— Debian
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2010-4158?
CVE-2010-4158 has been classified as a medium severity vulnerability.
How do I fix CVE-2010-4158?
To fix CVE-2010-4158, you need to update to the recommended kernel versions provided in the vendor's advisory.
Who is affected by CVE-2010-4158?
CVE-2010-4158 affects certain versions of the Linux kernel across various distributions.
What type of vulnerability is CVE-2010-4158?
CVE-2010-4158 is a memory leak vulnerability that allows unprivileged users to read kernel stack memory.
Can CVE-2010-4158 be exploited remotely?
CVE-2010-4158 does not appear to facilitate remote exploitation, but it allows local privilege escalation.