CVE-2010-3858
Linux Kernel < 2.6.36 - Denial of Service
Title source: ruleDescription
The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, which allows local users to cause a denial of service (system crash) via a crafted exec system call, a related issue to CVE-2010-2240.
Exploits (1)
References (20)
Scores
EPSS
0.0015
EPSS Percentile
35.0%
Details
CWE
CWE-400
Status
published
Products (5)
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
debian/debian_linux
5.0
linux/linux_kernel
< 2.6.36
Published
Nov 30, 2010
Tracked Since
Feb 18, 2026