Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
References
Configurations
History
No history.
Information
Published : 2010-12-29 18:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3859
Mitre link : CVE-2010-3859
CVE.ORG link : CVE-2010-3859
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
CWE
CWE-787
Out-of-bounds Write