2.1
CVSSv2

CVE-2008-0010

Published: 12/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 220
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 up to and including 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.22

linux linux kernel 2.6.22.1

linux linux kernel 2.6.23

linux linux kernel 2.6.23.7

linux linux kernel 2.6.23.9

linux linux kernel 2.6.22.16

linux linux kernel 2.6.22.3

linux linux kernel 2.6.23.1

linux linux kernel 2.6.23.14

linux linux kernel 2.6.22.6

linux linux kernel 2.6.22.7

linux linux kernel 2.6.23.4

linux linux kernel 2.6.23.5

linux linux kernel 2.6.23.6

linux linux kernel 2.6.22.4

linux linux kernel 2.6.22.5

linux linux kernel 2.6.23.2

linux linux kernel 2.6.23.3

linux linux kernel 2.6.24

Vendor Advisories

The vmsplice system call did not properly verify address arguments passed by user space processes, which allowed local attackers to overwrite arbitrary kernel memory, gaining root privileges (CVE-2008-0010, CVE-2008-0600) In the vserver-enabled kernels, a missing access check on certain symlinks in /proc enabled local attackers to access resources ...

Exploits

/* * diane_lane_fucked_hardc * * Linux vmsplice Local Root Exploit * By qaaz * * Linux 2623 - 2624 */ #define _GNU_SOURCE #include <stdioh> #include <errnoh> #include <stdlibh> #include <stringh> #include <unistdh> #include <sys/uioh> #define TARGET_PATTERN " sys_vm86old" #define TARGET_SYSCAL ...
/* * jessica_biel_naked_in_my_bedc * * Dovalim z knajpy a cumim ze Wojta zas nema co robit, kura * Gizdi, tutaj mate cosyk na hrani, kym aj totok vykeca * Stejnak je to stare jak cyp a aj jakesyk rozbite * * Linux vmsplice Local Root Exploit * By qaaz * * Linux 2617 - 26241 * * This is quite old code and I had to rewrite it to ...