CVE-2010-2538
MEDIUMLinux Kernel < 2.6.35 - Information Disclosure
Title source: ruleDescription
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
Scores
CVSS v3
5.5
EPSS
0.0008
EPSS Percentile
22.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
Status
draft
Affected Products (7)
linux/linux_kernel
< 2.6.35
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
suse/linux_enterprise_desktop
suse/linux_enterprise_high_availability_extension
suse/linux_enterprise_server
Timeline
Published
Sep 30, 2010
Tracked Since
Feb 18, 2026