The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-12-10T18:00:00

Updated: 2024-08-07T03:26:11.896Z

Reserved: 2010-10-08T00:00:00

Link: CVE-2010-3861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-12-10T19:00:04.127

Modified: 2024-11-21T01:19:46.517

Link: CVE-2010-3861

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-10-08T00:00:00Z

Links: CVE-2010-3861 - Bugzilla