Vulnerability Report

CVE-2010-4249

Title: Linux Linux Kernel Denial of Service (DoS)

DoS

Proof Of Concept

PoC Available for CVE-2010-4249

CWE Category CWE-400
Published Date Nov 29, 2010
Modified Date Jun 16, 2026
Exploit Status Available
Score 4.9 CVSS v2.0
Exploit Probability (EPSS)
0.89%

Vulnerability Summary

CVE-2010-4249: The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets.

Impacted Vendors

Reference Links

http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=9915672d41273f5b77f1b3c29b391ffb7732b84b http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.html http://lkml.org/lkml/2010/11/23/395 http://lkml.org/lkml/2010/11/23/450 http://lkml.org/lkml/2010/11/25/8 http://marc.info/?l=linux-netdev&m=129059035929046&w=2 http://secunia.com/advisories/42354 http://secunia.com/advisories/42745 http://secunia.com/advisories/42890 http://secunia.com/advisories/42963 http://secunia.com/advisories/46397 http://www.exploit-db.com/exploits/15622/ http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.37-rc3-next-20101125.bz2 http://www.openwall.com/lists/oss-security/2010/11/24/10 http://www.openwall.com/lists/oss-security/2010/11/24/2 http://www.redhat.com/support/errata/RHSA-2011-0007.html http://www.redhat.com/support/errata/RHSA-2011-0162.html http://www.securityfocus.com/archive/1/520102/100/0/threaded http://www.securityfocus.com/bid/45037 http://www.vmware.com/security/advisories/VMSA-2011-0012.html http://www.vupen.com/english/advisories/2010/3321 http://www.vupen.com/english/advisories/2011/0168 https://bugzilla.redhat.com/show_bug.cgi?id=656756 http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=9915672d41273f5b77f1b3c29b391ffb7732b84b http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.html http://lkml.org/lkml/2010/11/23/395 http://lkml.org/lkml/2010/11/23/450 http://lkml.org/lkml/2010/11/25/8 http://marc.info/?l=linux-netdev&m=129059035929046&w=2 http://secunia.com/advisories/42354 http://secunia.com/advisories/42745 http://secunia.com/advisories/42890 http://secunia.com/advisories/42963 http://secunia.com/advisories/46397 http://www.exploit-db.com/exploits/15622/ http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.37-rc3-next-20101125.bz2 http://www.openwall.com/lists/oss-security/2010/11/24/10 http://www.openwall.com/lists/oss-security/2010/11/24/2 http://www.redhat.com/support/errata/RHSA-2011-0007.html http://www.redhat.com/support/errata/RHSA-2011-0162.html http://www.securityfocus.com/archive/1/520102/100/0/threaded http://www.securityfocus.com/bid/45037 http://www.vmware.com/security/advisories/VMSA-2011-0012.html http://www.vupen.com/english/advisories/2010/3321 http://www.vupen.com/english/advisories/2011/0168 https://bugzilla.redhat.com/show_bug.cgi?id=656756
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
4.9
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:L/AC:L/Au:N/C:N/I:N/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2010-4249 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/15622
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:L/AC:L/Au:N/C:N/I:N/A:C

Affected Stack

No specific products linked.