CVE-2010-3850 describes a privilege escalation vulnerability in the Linux kernel's Econet networking functionality (specifically, the ec_dev_ioctl function in net/econet/af_econet.c). It allows local users to bypass access restrictions and configure Econet addresses via an SIOCSIFADDR ioctl call without requiring the CAP_NET_ADMIN capability, affecting various Linux distributions including Canonical, Debian, and SUSE. The vulnerability has a low CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of partial integrity. While not actively exploited in the wild (not in KEV or Hot List), exploit code exists on ExploitDB (e.g., "Half-Nelson.c"), though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.36.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp1:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.