CVE-2008-0009

The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
linuxlinux_kernel
2.6.22
linuxlinux_kernel
2.6.22:rc6
linuxlinux_kernel
2.6.22.1
linuxlinux_kernel
2.6.22.3
linuxlinux_kernel
2.6.22.4
linuxlinux_kernel
2.6.22.5
linuxlinux_kernel
2.6.22.6
linuxlinux_kernel
2.6.22.7
linuxlinux_kernel
2.6.22.16
linuxlinux_kernel
2.6.23
linuxlinux_kernel
2.6.23:rc1
linuxlinux_kernel
2.6.23:rc2
linuxlinux_kernel
2.6.23.1
linuxlinux_kernel
2.6.23.2
linuxlinux_kernel
2.6.23.3
linuxlinux_kernel
2.6.23.4
linuxlinux_kernel
2.6.23.5
linuxlinux_kernel
2.6.23.6
linuxlinux_kernel
2.6.23.7
linuxlinux_kernel
2.6.23.9
linuxlinux_kernel
2.6.23.14
linuxlinux_kernel
2.6.24:rc2
linuxlinux_kernel
2.6.24:rc3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
gutsy
dne
feisty
dne
edgy
dne
dapper
dne
linux-source-2.6.15
gutsy
dne
feisty
dne
edgy
dne
dapper
not-affected
linux-source-2.6.17
gutsy
dne
feisty
dne
edgy
not-affected
dapper
dne
linux-source-2.6.20
gutsy
dne
feisty
not-affected
edgy
dne
dapper
dne
linux-source-2.6.22
gutsy
not-affected
feisty
dne
edgy
dne
dapper
dne