5.5
CVSSv3

CVE-2008-4302

Published: 29/09/2008 Updated: 15/02/2024
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

fs/splice.c in the splice subsystem in the Linux kernel prior to 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 4.0

redhat enterprise linux 5.0

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that resolve several security issues and fixvarious bugs are now available for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedH ...

Exploits

source: wwwsecurityfocuscom/bid/31201/info The Linux kernel is prone to a local denial-of-service vulnerability Attackers can exploit this issue to cause the kernel to crash, denying service to legitimate users This issue affects versions prior to Linux kernel 26222 [global] bs=8k iodepth=1024 iodepth_batch=60 randrepeat=1 size= ...