CVE-2010-3858 describes a denial-of-service vulnerability in the Linux kernel (before version 2.6.36) affecting 32-bit applications on 64-bit platforms when CONFIG_STACK_GROWSDOWN is enabled. This flaw allows local users to crash the system via a crafted exec system call due to improper stack memory restriction for arguments and environment. With a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), it indicates a low-complexity local attack leading to a complete system availability loss. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-15619) exists, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* | ||
10.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.