Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3850

21
FAUCET Score

CVE-2010-3850 describes a privilege escalation vulnerability in the Linux kernel's Econet networking functionality (specifically, the ec_dev_ioctl function in net/econet/af_econet.c). It allows local users to bypass access restrictions and configure Econet addresses via an SIOCSIFADDR ioctl call without requiring the CAP_NET_ADMIN capability, affecting various Linux distributions including Canonical, Debian, and SUSE. The vulnerability has a low CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of partial integrity. While not actively exploited in the wild (not in KEV or Hot List), exploit code exists on ExploitDB (e.g., "Half-Nelson.c"), though there is no evidence of widespread community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.36.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp1:*:*:*:*:*:*
9CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.80%
Probability of exploitation in next 30 days
EPSS Percentile
52.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-17787 · Sep 5, 2011
This CVE's current EPSS score of 0.0080 is in the 87th percentile among its peer group of 2,096 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2010-3850

kernel: multiple vulnerabilities in Linux AF_ECONET

References

archives.neohapsis.com / archives/fulldisclosure/2010-12/0086.html
Broken Link
git.kernel.org
lists.opensuse.org / opensuse-security-announce/2011-01/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-02/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-02/msg00002.html
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/11/30/1
Mailing ListPatchThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
secunia.com / advisories/43056
Third Party Advisory
secunia.com / advisories/43291
Third Party Advisory
debian.org / security/2010/dsa-2126
Third Party Advisory
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.36.2
Broken Link
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
ubuntu.com / usn/USN-1023-1
Third Party Advisory
vupen.com / english/advisories/2011/0213
Third Party Advisory
vupen.com / english/advisories/2011/0298
Third Party Advisory
vupen.com / english/advisories/2011/0375
Third Party Advisory