PT-2008-6869 · Linux Foundation+2 · Linux+2

Eugene Teo

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2008-3528

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions linux-headers-2.6.18-6 versions 2.6.18-6 and earlier linux-image-2.6.18-6 versions 2.6.18-6 and earlier linux-modules-2.6.18-6 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-686-bigmem versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-generic versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-legacy versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-footbridge versions 2.6.18-6 and earlier linux-headers-2.6.18-6-iop32x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-itanium versions 2.6.18-6 and earlier linux-headers-2.6.18-6-k7 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-mckinley versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc64-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc-miboot versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-qemu versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r3k-kn02 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r4k-ip22 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r4k-kn04 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r5k-cobalt versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r5k-ip32 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-s390 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-s390x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sb1-bcm91250a versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sb1a-bcm91480b versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc32 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc64-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-alpha versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-k7 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-powerpc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-powerpc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-s390x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-sparc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver-amd64 versions 2.6.18-6 and earlier kernel-rt versions 2.6.18-6 and earlier kernel-rt debug versions 2.6.18-6 and earlier
Description The issue is related to multiple vulnerabilities in the Linux kernel, specifically in the Debian GNU/Linux operating system. These vulnerabilities can be exploited remotely, leading to a denial of service (temporary system hang) due to the error-reporting functionality not limiting the number of printk console messages that report directory corruption. The exploitation can occur when mounting a filesystem with corrupted dir->i size and dir->i blocks values and performing read or write operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-00886
BDU:2015-01470
BDU:2015-01471
BDU:2015-01472
BDU:2015-01473
BDU:2015-01474
BDU:2015-01475
BDU:2015-01476
BDU:2015-01477
BDU:2015-01478
BDU:2015-01479
BDU:2015-01480
BDU:2015-01481
BDU:2015-01482
BDU:2015-01483
BDU:2015-01484
BDU:2015-01485
BDU:2015-01486
BDU:2015-01487
BDU:2015-01488
BDU:2015-01489
BDU:2015-01490
BDU:2015-01491
BDU:2015-01492
BDU:2015-01493
BDU:2015-01494
BDU:2015-01495
BDU:2015-01496
BDU:2015-01497
BDU:2015-01498
BDU:2015-01499
BDU:2015-01500
BDU:2015-01501
BDU:2015-01502
BDU:2015-01503
BDU:2015-01504
BDU:2015-01505
BDU:2015-01506
BDU:2015-01507
BDU:2015-01508
BDU:2015-01509
BDU:2015-01510
BDU:2015-01511
BDU:2015-01512
BDU:2015-01513
BDU:2015-01514
BDU:2015-01515
BDU:2015-01516
BDU:2015-01517
BDU:2015-01518
BDU:2015-01519
BDU:2015-01520
BDU:2015-01521
BDU:2015-01522
BDU:2015-01523
BDU:2015-01524
BDU:2015-01525
BDU:2015-01526
BDU:2015-01527
BDU:2015-01528
BDU:2015-01529
BDU:2015-01530
BDU:2015-01531
BDU:2015-01532
BDU:2015-01533
BDU:2015-01534
BDU:2015-01535
BDU:2015-01536
BDU:2015-01537
BDU:2015-01538
BDU:2015-01539
BDU:2015-01540
BDU:2015-01541
BDU:2015-01542
BDU:2015-01543
BDU:2015-01544
BDU:2015-01545
BDU:2015-01546
BDU:2015-01547
BDU:2015-01548
BDU:2015-01549
BDU:2015-01550
BDU:2015-01551
BDU:2015-01552
BDU:2015-01553
BDU:2015-01554
BDU:2015-01555
BDU:2015-01556
BDU:2015-01557
BDU:2015-01558
BDU:2015-01559
BDU:2015-01560
BDU:2015-01561
BDU:2015-01562
BDU:2015-01563
BDU:2015-01564
BDU:2015-01565
BDU:2015-01566
BDU:2015-01567
BDU:2015-01568
BDU:2015-01569
BDU:2015-01570
BDU:2015-01571
BDU:2015-01572
BDU:2015-01573
BDU:2015-01574
BDU:2015-01575
BDU:2015-01576
BDU:2015-01577
BDU:2015-01578
BDU:2015-01579
BDU:2015-01580
BDU:2015-01581
BDU:2015-01582
BDU:2015-01583
BDU:2015-01584
BDU:2015-01585
BDU:2015-01586
BDU:2015-01587
BDU:2015-01588
BDU:2015-01589
BDU:2015-01590
BDU:2015-01591
BDU:2015-01592
BDU:2015-01593
BDU:2015-01594
BDU:2015-05034
BDU:2015-05035
CVE-2008-3528
DSA-1681-1
DSA-1687-1
RHSA-2008:0972
RHSA-2008_0972
RHSA-2009:0009
RHSA-2009:0326
RHSA-2009_0326

Affected Products

Debian
Linux
Red Hat