CVE-2010-4249 describes a denial-of-service vulnerability in the Linux kernel (before 2.6.37-rc3-next-20101125), specifically affecting Fedora and other Linux distributions. This flaw, categorized as CWE-400 (Uncontrolled Resource Consumption), allows a local attacker to cause a system hang by manipulating socketpair and sendmsg system calls with SOCK_SEQPACKET sockets. With a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), it indicates a low attack complexity but a high impact on availability. While not actively exploited in the wild (no KEV entry), a proof-of-concept exploit (EDB-15622) exists, though there is minimal community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:* | ||
2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37:rc1:*:*:*:*:*:* | ||
2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37:rc2:*:*:*:*:*:* | ||
13CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.