CVE-2010-4347

Linux Kernel < 2.6.36.2 - Privilege Escalation via ACPI Debugfs Custom Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4347. PoCs published by Jon Oberheide.

AI-analyzed exploit summary This exploit leverages a world-writable ACPI custom_method file in Linux kernels < 2.6.37-rc2 to inject malicious ACPI methods, overriding the LID device status query to overwrite kernel memory (sys_futimesat) and escalate privileges to root.

Description

The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jon Oberheide · clocallinux
https://www.exploit-db.com/exploits/15774

This exploit leverages a world-writable ACPI custom_method file in Linux kernels < 2.6.37-rc2 to inject malicious ACPI methods, overriding the LID device status query to overwrite kernel memory (sys_futimesat) and escalate privileges to root.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Linux Kernel < 2.6.37-rc2
No auth needed
Prerequisites: World-writable /sys/kernel/debug/acpi/custom_method · ACPI LID device presence · 64-bit system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (13)

Core 13
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=663542
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42778
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html
Exploit, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45408
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0298
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2010/12/15/3
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0012
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2010/12/15/7
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15774/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64155

Scores

EPSS 0.0220
EPSS Percentile 80.2%

Details

CWE
CWE-269
Status published
Products (3)
linux/linux_kernel < 2.6.36.2
opensuse/opensuse 11.3
suse/linux_enterprise_real_time_extension 11 sp1
Published Dec 22, 2010
Tracked Since Feb 18, 2026