// For flags

CVE-2010-1636

Linux Kernel 2.6.x - Btrfs Cloned File Security Bypass

Severity Score

2.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.

La funciĆ³n btrfs_ioctl_clone en fs/btrfs/ioctl.c en la funcionalidad btrfs del kernel de Linux v2.6.29 a v2.6.32, y posiblemente otras versiones, no garantiza que un descriptor de archivo clonado ha sido abierto solo para lectura, lo cual permite leer informaciĆ³n sensible de un descriptor de fichero de solo escritura a usuarios locales del sistema.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-04-29 CVE Reserved
  • 2010-05-18 First Exploit
  • 2010-06-07 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.1
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.1"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.2
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.2"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.3
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.3"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.4
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.4"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.5
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.5"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.29.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6.29.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.1
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.1"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.2
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.2"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.3
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.3"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.4
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.4"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.5
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.5"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.7
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.7"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.8
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.8"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.9
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.9"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.30.10
Search vendor "Linux" for product "Linux Kernel" and version "2.6.30.10"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.1
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.1"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.2
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.2"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.3
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.3"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.4
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.4"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.5
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.5"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.7
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.7"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.8
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.8"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.9
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.9"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.10
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.10"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.11
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.11"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.12
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.12"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.31.13
Search vendor "Linux" for product "Linux Kernel" and version "2.6.31.13"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.32
Search vendor "Linux" for product "Linux Kernel" and version "2.6.32"
-
Affected