Back to search
CVE-2008-0009
Published: Feb 12, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=431206
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1
x_refsource_CONFIRM
ADV-2008-0487
vdb-entry
x_refsource_VUPEN
20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference
mailing-list
x_refsource_BUGTRAQ
http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt
x_refsource_MISC
FEDORA-2008-1422
vendor-advisory
x_refsource_FEDORA
28896
third-party-advisory
x_refsource_SECUNIA
28835
third-party-advisory
x_refsource_SECUNIA
27799
vdb-entry
x_refsource_BID
FEDORA-2008-1423
vendor-advisory
x_refsource_FEDORA
27704
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now