CVE-2010-2240 is a critical vulnerability in the Linux kernel, specifically affecting versions before 2.6.27.52, 2.6.32.19, 2.6.34.4, and 2.6.35.2. It stems from improper separation of the stack and heap in the do_anonymous_page function, allowing local attackers to execute arbitrary code. The vulnerability carries a CVSS score of 7.2, indicating high severity due to its local attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, including articles related to "Stack Clash" flaws, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.27.51CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:*:*:*:*:*:*:* | ||
2.6.32.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32.1:*:*:*:*:*:*:* | ||
2.6.32.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32.2:*:*:*:*:*:*:* | ||
2.6.32.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.