PT-2003-1064 · Linux · Linux Kernel
Published
2003-02-19
·
Updated
2008-09-11
·
CVE-2003-0018
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4.10 through 2.4.21-pre4
Description
The issue affects the Linux kernel, allowing local attackers with write privileges to read portions of previously deleted files or cause file system corruption due to improper handling of the O DIRECT feature. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out locally.
Recommendations
For Linux kernel versions 2.4.10 through 2.4.21-pre4, consider updating to a version that properly handles the O DIRECT feature to prevent file system corruption and unauthorized access to deleted files. As a temporary workaround, restrict local write privileges to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel