Lucene search

K
prionPRIOn knowledge basePRION:CVE-2008-3528
HistorySep 27, 2008 - 10:30 a.m.

Memory corruption

2008-09-2710:30:00
PRIOn knowledge base
www.prio-n.com
7

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.9%

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

CPENameOperatorVersion
linux_kerneleq2.6.26.5

References

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.9%