CVE Database
/

CVE-2008-3528

Back to search

CVE-2008-3528

Published: Sep 27, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

VendorProductVersions

n/a

n/a

affected
n/a

References

32998
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:0326
vendor-advisory
x_refsource_REDHAT
MDVSA-2008:224
vendor-advisory
x_refsource_MANDRIVA
37471
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0972
vendor-advisory
x_refsource_REDHAT
SUSE-SA:2008:052
vendor-advisory
x_refsource_SUSE
33758
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:0009
vendor-advisory
x_refsource_REDHAT
SUSE-SA:2008:053
vendor-advisory
x_refsource_SUSE
kernel-errorreporting-dos(45720)
vdb-entry
x_refsource_XF
SUSE-SA:2008:056
vendor-advisory
x_refsource_SUSE
USN-662-1
vendor-advisory
x_refsource_UBUNTU
33586
third-party-advisory
x_refsource_SECUNIA
32509
third-party-advisory
x_refsource_SECUNIA
32709
third-party-advisory
x_refsource_SECUNIA
DSA-1687
vendor-advisory
x_refsource_DEBIAN
32356
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:8642
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:10852
vdb-entry
signature
x_refsource_OVAL
32759
third-party-advisory
x_refsource_SECUNIA
33180
third-party-advisory
x_refsource_SECUNIA
32370
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:051
vendor-advisory
x_refsource_SUSE
32799
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:057
vendor-advisory
x_refsource_SUSE
SUSE-SR:2008:025
vendor-advisory
x_refsource_SUSE
DSA-1681
vendor-advisory
x_refsource_DEBIAN
ADV-2009-3316
vdb-entry
x_refsource_VUPEN
20081112 rPSA-2008-0316-1 kernel
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now