CVE-2010-4565 describes an information disclosure vulnerability in the Linux kernel's Controller Area Network (CAN) Broadcast Manager (bcm_connect function in net/can/bcm.c), affecting versions 2.6.36 and earlier. This flaw allows local users to obtain potentially sensitive kernel memory addresses by listing a publicly accessible file whose filename contains this information. With a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), the vulnerability is of low severity, requiring local access and having a low attack complexity, with the primary impact being information disclosure. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.