2.1
CVSSv2

CVE-2010-1636

Published: 08/06/2010 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 up to and including 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.31

linux linux kernel 2.6.29.3

linux linux kernel 2.6.31.9

linux linux kernel 2.6.31.3

linux linux kernel 2.6.30.10

linux linux kernel 2.6.31.12

linux linux kernel 2.6.29

linux linux kernel 2.6.31.4

linux linux kernel 2.6.32

linux linux kernel 2.6.31.6

linux linux kernel 2.6.31.10

linux linux kernel 2.6.31.1

linux linux kernel 2.6.30.7

linux linux kernel 2.6.29.4

linux linux kernel 2.6.31.7

linux linux kernel 2.6.30.8

linux linux kernel 2.6.30.9

linux linux kernel 2.6.29.1

linux linux kernel 2.6.30.4

linux linux kernel 2.6.29.6

linux linux kernel 2.6.30.2

linux linux kernel 2.6.30.6

linux linux kernel 2.6.30.1

linux linux kernel 2.6.31.5

linux linux kernel 2.6.31.11

linux linux kernel 2.6.29.2

linux linux kernel 2.6.31.13

linux linux kernel 2.6.31.8

linux linux kernel 2.6.31.2

linux linux kernel 2.6.30.5

linux linux kernel 2.6.30

linux linux kernel 2.6.30.3

linux linux kernel 2.6.29.5

Exploits

/* source: wwwsecurityfocuscom/bid/40241/info The Linux Kernel is prone to a security-bypass vulnerability that affects the Btrfs filesystem implementation An attacker can exploit this issue to clone a file only open for writing This may allow attackers to obtain sensitive data or launch further attacks */ #include <fcntlh> # ...