Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3865

23
FAUCET Score

CVE-2010-3865 describes an integer overflow in the Linux kernel's Reliable Datagram Sockets (RDS) functionality, specifically within the rds_rdma_pages function, affecting Linux, openSUSE, and SUSE distributions. This vulnerability carries a CVSS score of 7.2, indicating high severity, as a local attacker can exploit it with low complexity to cause a denial of service (system crash) and potentially execute arbitrary code. Despite its potential impact, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this decade-old flaw.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.6.36CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
11.2CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp1:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_real_time:11:sp1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 64th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: cm1 kernel 5.4.72-11 on CBL Mariner 1.0Fixed in: 5.4.72-11
microsoftpatch availablevia msrc
Product: 19217-16820Fixed in: 5.4.72-11
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.4.72-11
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.4.72-11
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-194.32.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-71.14.1.el6
View patch

Vendor Advisories (3)

microsoft2020-Sep/CVE-2010-3865

CVE-2010-3865

Sep 8, 2020
microsoft2011-Jan/CVE-2010-3865Important

Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request which triggers a buffer overflow.

Jan 2, 2011
redhatCVE-2010-3865Important

kernel: iovec integer overflow in net/rds/rdma.c

Oct 29, 2010

References

lists.opensuse.org / opensuse-security-announce/2010-11/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-02/msg00000.html
Mailing ListThird Party Advisory
secunia.com / advisories/42778
Third Party Advisory
secunia.com / advisories/42789
Third Party Advisory
secunia.com / advisories/42801
Third Party Advisory
secunia.com / advisories/42890
Third Party Advisory
secunia.com / advisories/46397
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/62881
Third Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2010/10/29/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/11/01/1
Mailing ListThird Party Advisory
redhat.com / support/errata/RHSA-2011-0004.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-0007.html
Third Party Advisory
securityfocus.com / archive/1/520102/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/44549
Third Party AdvisoryVDB Entry
spinics.net / lists/netdev/msg145359.html
Mailing ListPatchThird Party Advisory
spinics.net / lists/netdev/msg145397.html
Mailing ListThird Party Advisory
vmware.com / security/advisories/VMSA-2011-0012.html
Third Party Advisory
vupen.com / english/advisories/2011/0012
Third Party Advisory
vupen.com / english/advisories/2011/0024
Third Party Advisory
vupen.com / english/advisories/2011/0298
Third Party Advisory