The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T03:26:11.896Z

Reserved: 2010-10-08T00:00:00

Link: CVE-2010-3861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-12-10T19:00:04.127

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-3861

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-10-08T00:00:00Z

Links: CVE-2010-3861 - Bugzilla