CVE-2010-4076 describes an information disclosure vulnerability in the Linux kernel (2.6.36.1 and earlier) affecting the rs_ioctl function within the amiserial.c driver. A local attacker can exploit this flaw by making a TIOCGICOUNT ioctl call, which improperly initializes a structure member, leading to the disclosure of potentially sensitive information from kernel stack memory. This vulnerability has a low CVSS score of 1.9, indicating low severity due to requiring local access and medium attack complexity, with the only impact being partial confidentiality. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.36.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.