PT-2008-6905 · Linux+3 · Linux Kernel+3

Eugene Teo

+1

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2008-3275

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel versions 2.4.9 Red Hat Enterprise Linux kernel versions 2.4.18 Debian GNU/Linux linux-headers versions 2.6.24-etchnhalf.1-all-mips Debian GNU/Linux linux-headers versions 2.6.24-etchnhalf.1-r4k-ip22 Debian GNU/Linux linux-headers versions 2.6.24-etchnhalf.1-r5k-ip32 openSUSE kernel-rt debug-debugsource (affected versions not specified) openSUSE kernel-rt debug-debuginfo (affected versions not specified) Linux kernel versions prior to 2.6.25.15
Description The issue concerns multiple vulnerabilities in various Linux kernel packages across different operating systems, including Red Hat Enterprise Linux and Debian GNU/Linux. These vulnerabilities can lead to disruptions in confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Specifically, functions like real lookup and lookup hash in the Linux kernel's vfs implementation have issues that allow local users to cause a denial of service by attempting file creations within deleted directories.
Recommendations For Red Hat Enterprise Linux kernel version 2.4.9, update to a version that includes the necessary security patches. For Red Hat Enterprise Linux kernel version 2.4.18, update to a version that includes the necessary security patches. For Debian GNU/Linux linux-headers version 2.6.24-etchnhalf.1-all-mips, update to a version that includes the necessary security patches. For Debian GNU/Linux linux-headers version 2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches. For Debian GNU/Linux linux-headers version 2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches. For openSUSE kernel-rt debug-debugsource and kernel-rt debug-debuginfo, update to versions that include the necessary security patches. For Linux kernel versions prior to 2.6.25.15, update to version 2.6.25.15 or later to resolve the issue. As a temporary workaround, consider restricting access to vulnerable kernel functions until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02636
BDU:2015-02637
BDU:2015-02638
BDU:2015-02639
BDU:2015-02640
BDU:2015-05014
BDU:2015-05015
BDU:2015-05016
BDU:2015-05017
BDU:2015-06237
BDU:2015-06238
BDU:2015-06242
BDU:2015-06244
BDU:2015-06253
BDU:2015-06254
BDU:2015-06257
BDU:2015-06259
BDU:2015-06268
BDU:2015-06269
BDU:2015-06272
BDU:2015-06273
BDU:2015-06274
CVE-2008-3275
DSA-1630-1
DSA-1636-1
RHSA-2008:0787
RHSA-2008:0857
RHSA-2008:0885
RHSA-2008:0973
RHSA-2008_0885
RHSA-2009:0001
RHSA-2009:0014
RHSA-2009_0014

Affected Products

Debian
Linux Kernel
Red Hat
Opensuse