kernel: RDS sockets local privilege escalation
Published Dec 6, 2010 ·Due Jun 2, 2023
7.8
HIGHCVSS 3.1
EPSS 14.47%
Description
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Affected products
No data.
Configuration 1
- < 2.6.36
Configuration 2
- 11.2
- 11.3
- 11
- 11
- 11
Configuration 3
- 6.06
- 8.04
- 9.04
- 9.10
- 10.04
- 10.10
Configuration 4
- 5.0
- 6.0
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-194.17.4.el5
Fixed · RHSA-2010:0792
Red Hat Enterprise Linux 6
kernel-0:2.6.32-71.7.1.el6
Fixed · RHSA-2010:0842
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-194.17.4.el5 | Fixed | RHSA-2010:0792 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-71.7.1.el6 | Fixed | RHSA-2010:0842 |
No package ranges for this CVE.
Remediation
Red Hat statement
The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG did not include support for the RDS Protocol, and therefore are not affected by this issue. Updates for Red Hat Enterprise Linux 5 and 6 are available to address this flaw.
Red Hat mitigation
For users that do not run applications that use RDS, you can prevent the rds module from being loaded by adding the following entry to the end of the /etc/modprobe.d/blacklist file: blacklist rds This way, the rds module cannot be loaded accidentally, which may occur if an application that requires RDS is started. A reboot is not necessary for this change to take effect but do make sure the module is not loaded in the first place. You can verify that by running: lsmod | grep rds You may also consider removing the CAP_SYS_MODULE capability from the current global capability set to prevent kernel modules from being loaded or unloaded. The CAP_SYS_MODULE has a capability number of 16 (see linux/capability.h). The default value has all the bits set. To remove this capability, you have to clear the 16th bit of the default 32-bit value, e.g. 0xffffff ^ (1 << 16): echo 0xFFFEFFFF > /proc/sys/kernel/cap-bound
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
May 12, 2023
Patch Due
Jun 2, 2023
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 14.47% (0.14468) | 96.53th | v5 (v2026.06.15) |
| Aug 21, 2026 | 14.67% (0.14668) | 96.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.22% (0.11217) | 95.39th | v5 (v2026.06.15) |
| May 21, 2026 | 2.41% (0.02408) | 85.27th | v4 (v2025.03.14) |
| Apr 17, 2026 | 1.25% (0.01254) | 79.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.25% (0.02254) | 83.43th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00132) | 49.77th | v3 (v2023.03.01) |
| Jun 28, 2024 | 0.10% (0.00105) | 43.08th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.09% (0.00091) | 38.06th | v3 (v2023.03.01) |
| Jul 27, 2023 | 0.10% (0.00097) | 39.67th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.10% (0.00104) | 41.38th | v3 (v2023.03.01) |
| May 13, 2023 | 0.09% (0.00089) | 36.71th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00070) | 28.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.10% (0.02095) | 79.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.10% (0.02095) | 78.03th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.10% (0.02095) | 56.72th | v2 (v2022.01.01) |
References (24)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=799c10559d60f159ab2232203f222f18fa3c4a5f x_refsource_CONFIRMBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/155751/vReliable-Datagram-Sockets-RDS-rds_page_copy_user-Privilege-Escalation.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/46397 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://securitytracker.com/id?1024613 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.kb.cert.org/vuls/id/362983 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 x_refsource_CONFIRMBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0792.html vendor-advisoryx_refsource_REDHATBroken LinkThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.html vendor-advisoryx_refsource_REDHATBroken LinkThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1000-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2011-0012.html x_refsource_CONFIRMThird Party Advisory
- http://www.vsecurity.com/download/tools/linux-rds-exploit.c x_refsource_MISCBroken Link
- http://www.vsecurity.com/resources/advisory/20101019-1/ x_refsource_MISCBroken Link
- http://www.vupen.com/english/advisories/2011/0298 vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2010-3904 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=642896 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-3904
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3904 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2010-3904
- https://www.exploit-db.com/exploits/44677/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.