kernel: 64-bit Compatibility Mode Stack Pointer Underflow
Published Sep 24, 2010
7.8
HIGHCVSS 3.1
EPSS 3.53%
Description
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.
Affected products
No data.
Configuration 1
- ≤ 2.6.35.4
- 2.6.36
- 2.6.36
- 2.6.36
- 2.6.36
Configuration 3
- 11
- 11
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-169.el5rt
Fixed · RHSA-2010:0758
Red Hat Enterprise Linux 3 Extended Lifecycle Support
kernel-0:2.4.21-66.EL
Fixed · RHSA-2010:0882
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.29.1.EL
Fixed · RHSA-2010:0718
Red Hat Enterprise Linux 4.7 Z Stream
kernel-0:2.6.9-78.0.33.EL
Fixed · RHSA-2010:0719
Red Hat Enterprise Linux 5
kernel-0:2.6.18-194.11.4.el5
Fixed · RHSA-2010:0704
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.23.2.el5
Fixed · RHSA-2010:0711
Red Hat Enterprise Linux 5.4.Z - Server Only
kernel-0:2.6.18-164.25.2.el5
Fixed · RHSA-2010:0705
Red Hat Enterprise Linux 6
kernel-0:2.6.32-71.7.1.el6
Fixed · RHSA-2010:0842
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-169.el5rt | Fixed | RHSA-2010:0758 |
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | kernel-0:2.4.21-66.EL | Fixed | RHSA-2010:0882 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.29.1.EL | Fixed | RHSA-2010:0718 |
| Red Hat Enterprise Linux 4.7 Z Stream | kernel-0:2.6.9-78.0.33.EL | Fixed | RHSA-2010:0719 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-194.11.4.el5 | Fixed | RHSA-2010:0704 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.23.2.el5 | Fixed | RHSA-2010:0711 |
| Red Hat Enterprise Linux 5.4.Z - Server Only | kernel-0:2.6.18-164.25.2.el5 | Fixed | RHSA-2010:0705 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-71.7.1.el6 | Fixed | RHSA-2010:0842 |
No package ranges for this CVE.
Remediation
Red Hat statement
More information can be found in this kbase: https://access.redhat.com/kb/docs/DOC-40265.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.53% (0.03533) | 88.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.70% (0.03696) | 88.25th | v5 (v2026.06.15) |
| Jun 12, 2026 | 6.13% (0.06126) | 91.02th | v4 (v2025.03.14) |
| Feb 15, 2026 | 7.31% (0.07311) | 91.48th | v4 (v2025.03.14) |
| Dec 31, 2025 | 4.07% (0.04070) | 88.20th | v4 (v2025.03.14) |
| Dec 18, 2025 | 8.50% (0.08503) | 92.05th | v4 (v2025.03.14) |
| Nov 23, 2025 | 20.45% (0.20446) | 95.31th | v4 (v2025.03.14) |
| Oct 18, 2025 | 19.37% (0.19369) | 95.09th | v4 (v2025.03.14) |
| Oct 7, 2025 | 21.72% (0.21720) | 95.55th | v4 (v2025.03.14) |
| Sep 10, 2025 | 19.92% (0.19924) | 95.26th | v4 (v2025.03.14) |
| Jun 3, 2025 | 14.75% (0.14754) | 94.17th | v4 (v2025.03.14) |
| Apr 19, 2025 | 29.08% (0.29082) | 96.25th | v4 (v2025.03.14) |
| Mar 26, 2025 | 44.98% (0.44977) | 97.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 62.59% (0.62591) | 98.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.10th | v3 (v2023.03.01) |
| May 17, 2024 | 0.04% (0.00042) | 5.23th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 0.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.22% (0.03220) | 84.21th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.22% (0.03220) | 83.79th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.00% (0.04005) | 85.60th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.22% (0.03220) | 82.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.22% (0.03220) | 65.30th | v2 (v2022.01.01) |
References (31)
- http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0273.html mailing-listx_refsource_FULLDISCBroken Link
- http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0278.html mailing-listx_refsource_FULLDISCBroken Link
- http://blog.ksplice.com/2010/09/cve-2010-3081/ x_refsource_MISCBroken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c41d68a513c71e35a14f66d71782d27a79a81ea6 x_refsource_CONFIRM
- http://isc.sans.edu/diary.html?storyid=9574 x_refsource_MISCPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=oss-security&m=128461522230211&w=2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://secunia.com/advisories/42384 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/43315 third-party-advisoryx_refsource_SECUNIABroken Link
- http://sota.gen.nz/compat1/ x_refsource_MISCBroken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.36-rc4-git2.log x_refsource_CONFIRMBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:198 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:214 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:247 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0758.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0842.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0882.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/514938/30/30/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2010-0017.html x_refsource_CONFIRMThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2010/3083 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/3117 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2011/0298 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/kb/docs/DOC-40265 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2010-3081 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=634457 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-3081
- https://www.cve.org/CVERecord?id=CVE-2010-3081
Change history (0)
No recorded changes yet.