Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-4258

33
FAUCET Score

CVE-2010-4258 is a local privilege escalation vulnerability in the Linux kernel, specifically affecting versions before 2.6.36.2, including Fedora, openSUSE, and SUSE distributions. It stems from improper handling of KERNEL_DS get_fs values in the do_exit function, allowing local users to bypass access_ok restrictions. This flaw enables attackers to overwrite arbitrary kernel memory and gain root privileges through various triggers like BUGs, NULL pointer dereferences, or page faults, often leveraging clear_child_tid and splice system calls. The vulnerability has a CVSS score of 6.2 (Medium), indicating a local attack vector with high attack complexity but critical impact on confidentiality, integrity, and availability. Its EPSS score is low, suggesting it's not widely exploited in the wild, yet its FAUCET Risk Score is high at 86/100. While not listed in KEV or having Metasploit/Nuclei modules, an exploit (EDB-15704, "Full-Nelson.c") exists for Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04). Community discussion and media coverage are minimal, suggesting limited public attention despite the availability of exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.36.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
13CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
11.2CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.2MEDIUM

AV:L/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
1.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.66%
Probability of exploitation in next 30 days
EPSS Percentile
84.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-15704 · Dec 7, 2010
This CVE's current EPSS score of 0.0266 is in the 97th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 1Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2010-4258Moderate

kernel: failure to revert address limit override in OOPS error path

Dec 3, 2010

References

archives.neohapsis.com / archives/fulldisclosure/2010-12/0086.html
Broken Link
blog.nelhage.com / 2010/12/cve-2010-4258-from-dos-to-privesc
Third Party Advisory
code.google.com / p/chromium-os/issues/detail
Third Party Advisory
git.kernel.org
googlechromereleases.blogspot.com / 2011/01/chrome-os-beta-channel-update.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2010-December/052513.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-02/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-02/msg00002.html
Mailing ListThird Party Advisory
marc.info
PatchThird Party Advisory
openwall.com / lists/oss-security/2010/12/02/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/02/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/02/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/02/7
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/08/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/08/5
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/08/9
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/09/14
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2010/12/09/4
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/42745
Third Party Advisory
secunia.com / advisories/42778
Third Party Advisory
secunia.com / advisories/42801
Third Party Advisory
secunia.com / advisories/42932
Third Party Advisory
secunia.com / advisories/43056
Third Party Advisory
secunia.com / advisories/43291
Third Party Advisory
lkml.org / lkml/2010/12/1/543
Mailing ListPatchThird Party Advisory
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.36.2
Broken Link
mandriva.com / security/advisories
Third Party Advisory
vupen.com / english/advisories/2010/3321
Third Party Advisory
vupen.com / english/advisories/2011/0012
Third Party Advisory
vupen.com / english/advisories/2011/0124
Third Party Advisory
vupen.com / english/advisories/2011/0213
Third Party Advisory
vupen.com / english/advisories/2011/0298
Third Party Advisory
vupen.com / english/advisories/2011/0375
Third Party Advisory