← Vulnerability feed

Vulnerability record · CVE-2010-2942 · published 21 September 2010

CVE-2010-2942: Linux kernel memory leak vulnerability

Linux · Linux Kernel

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.

5.5 CVSS 3.1 Medium EPSS 0.42% · top 66.1% CWE-401 · Memory leak
5.5CVSS 3.1 base score, v2 2.1
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
46References
16 Jun 2026Last modified by NVD

Description

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=1c40be12f7d8ca1d387510d39787b12e512a7ce8
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00000.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html Mailing ListThird Party Advisory
http://patchwork.ozlabs.org/patch/61857/ Mailing ListPatchThird Party Advisory
http://secunia.com/advisories/41512 Broken Link
http://secunia.com/advisories/46397 Broken Link
http://support.avaya.com/css/P8/documents/100113326 Third Party Advisory
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc2 Broken Link
http://www.openwall.com/lists/oss-security/2010/08/18/1 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2010/08/19/4 Mailing ListPatchThird Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0723.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0771.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0779.html Broken Link
http://www.securityfocus.com/archive/1/520102/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/42529 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-1000-1 Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2011-0012.html Third Party Advisory
http://www.vupen.com/english/advisories/2010/2430 Broken Link
http://www.vupen.com/english/advisories/2011/0298 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=624903 Issue TrackingPatchThird Party Advisory
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=1c40be12f7d8ca1d387510d39787b12e512a7ce8
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00000.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html Mailing ListThird Party Advisory
http://patchwork.ozlabs.org/patch/61857/ Mailing ListPatchThird Party Advisory
http://secunia.com/advisories/41512 Broken Link
http://secunia.com/advisories/46397 Broken Link
http://support.avaya.com/css/P8/documents/100113326 Third Party Advisory
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.36-rc2 Broken Link
http://www.openwall.com/lists/oss-security/2010/08/18/1 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2010/08/19/4 Mailing ListPatchThird Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0723.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0771.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0779.html Broken Link
http://www.securityfocus.com/archive/1/520102/100/0/threaded Third Party AdvisoryVDB Entry

Track CVE-2010-2942 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7029Avaya aura communication manager cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager…EPSS 0.43%8.1CVE-2010-2943Linux kernel information exposure vulnerabilityThe xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote a…EPSS 17%7.8CVE-2010-2492Linux kernel classic buffer overflow vulnerabilityBuffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow loc…EPSS 0.43%7.8CVE-2010-2798Linux kernel null pointer dereference vulnerabilityThe gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with s…EPSS 0.41%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%7.5CVE-2018-15617Avaya aura communication manager vulnerabilityA vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to c…EPSS 2.2%7.1CVE-2009-3939Linux kernel incorrect permission assignment vulnerabilityThe poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t…EPSS 0.44%6.7CVE-2024-7477Avaya aura system manager sql injection vulnerabilityA SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary que…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2010-2942), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.