Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0009
HistoryFeb 12, 2008 - 12:00 a.m.

CVE-2008-0009

2008-02-1200:00:00
ubuntu.com
ubuntu.com
26

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

9.8%

The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22
through 2.6.24 does not validate a certain userspace pointer before
dereference, which might allow local users to access arbitrary kernel
memory locations.

Bugs

Notes

Author Note
jdstrand dapper-gutsy not affected. Only 2.6.23 - 2.6.24. See: http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt local root exploit on hardy (exploit code doesn’t exist yet) amitk will upload 2.6.24.2 for hardy soon

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

9.8%