CVE-2010-2538

MEDIUM

Linux Kernel < 2.6.35 - Information Disclosure

Title source: rule

Description

Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (7)

linux/linux_kernel < 2.6.35
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
suse/linux_enterprise_desktop
suse/linux_enterprise_high_availability_extension
suse/linux_enterprise_server

Timeline

Published Sep 30, 2010
Tracked Since Feb 18, 2026