CVE-2010-4258 is a local privilege escalation vulnerability in the Linux kernel, specifically affecting versions before 2.6.36.2, including Fedora, openSUSE, and SUSE distributions. It stems from improper handling of KERNEL_DS get_fs values in the do_exit function, allowing local users to bypass access_ok restrictions. This flaw enables attackers to overwrite arbitrary kernel memory and gain root privileges through various triggers like BUGs, NULL pointer dereferences, or page faults, often leveraging clear_child_tid and splice system calls. The vulnerability has a CVSS score of 6.2 (Medium), indicating a local attack vector with high attack complexity but critical impact on confidentiality, integrity, and availability. Its EPSS score is low, suggesting it's not widely exploited in the wild, yet its FAUCET Risk Score is high at 86/100. While not listed in KEV or having Metasploit/Nuclei modules, an exploit (EDB-15704, "Full-Nelson.c") exists for Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04). Community discussion and media coverage are minimal, suggesting limited public attention despite the availability of exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.36.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
13CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:* | ||
11.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.