CVE-2010-0415

Linux Kernel < 2.6.33 - Arbitrary Kernel Memory Read and Denial of Service via Invalid Node Values

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0415. PoCs published by spender.

AI-analyzed exploit summary This exploit leverages a vulnerability in the Linux kernel's move_pages() system call (CVE-2010-0415) to leak kernel memory by manipulating node bitmaps. It allows an attacker to read arbitrary kernel memory by abusing the node_states or node_online_map structures.

Description

The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.

Exploits (1)

exploitdb WORKING POC
by spender · clocallinux
https://www.exploit-db.com/exploits/40810

This exploit leverages a vulnerability in the Linux kernel's move_pages() system call (CVE-2010-0415) to leak kernel memory by manipulating node bitmaps. It allows an attacker to read arbitrary kernel memory by abusing the node_states or node_online_map structures.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel 2.6.18+
No auth needed
Prerequisites: Access to a vulnerable Linux kernel with the move_pages system call available
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (28)

Core 28
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-914-1
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0147.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9399
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:198
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38144
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=562582
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0161.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/07/2
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0638
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38557
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035070.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38779
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/07/1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38922
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-1996
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43315
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:066
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39033
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/08/2
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2005
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38492

Scores

EPSS 0.0182
EPSS Percentile 75.9%

Details

Status published
Products (50)
linux/linux_kernel 2.6.0
linux/linux_kernel 2.6.1
linux/linux_kernel 2.6.2
linux/linux_kernel 2.6.3
linux/linux_kernel 2.6.4
linux/linux_kernel 2.6.5
linux/linux_kernel 2.6.6
linux/linux_kernel 2.6.7
linux/linux_kernel 2.6.8
linux/linux_kernel 2.6.8.1
... and 40 more
Published Feb 17, 2010
Tracked Since Feb 18, 2026