CVE-2010-4074
Summary
| CVE | CVE-2010-4074 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-11-29 16:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 5.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.36 | - | All | All |
| Operating System | Linux | Linux Kernel | 2.6.36 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.36 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.36 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.36 | rc4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2126-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| oss-security - Re: CVE request: multiple kernel stack memory disclosures | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| Red Hat update for kernel - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| LKML: Dan Rosenberg: [PATCH] drivers/usb/serial/mos*: prevent reading uninitialized stack memory | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Mailing List, Patch, Third Party Advisory |
| oss-security - CVE request: multiple kernel stack memory disclosures | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Linux Kernel TIOCGICOUNT CVE-2010-4074 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Broken Link |
| oss-security - Re: CVE request: multiple kernel stack memory disclosures | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| oss-security - Re: CVE request: multiple kernel stack memory disclosures | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Bug 648659 – CVE-2010-4074 kernel: drivers/usb/serial/mos*.c: reading uninitialized stack memory | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.