CVE-2008-2148

The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
linuxlinux_kernel
2.6.22
linuxlinux_kernel
2.6.22.1
linuxlinux_kernel
2.6.22.2
linuxlinux_kernel
2.6.22.3
linuxlinux_kernel
2.6.22.4
linuxlinux_kernel
2.6.22.5
linuxlinux_kernel
2.6.22.6
linuxlinux_kernel
2.6.22.7
linuxlinux_kernel
2.6.22.8
linuxlinux_kernel
2.6.22.9
linuxlinux_kernel
2.6.22.10
linuxlinux_kernel
2.6.22.11
linuxlinux_kernel
2.6.22.12
linuxlinux_kernel
2.6.22.13
linuxlinux_kernel
2.6.22.14
linuxlinux_kernel
2.6.22.15
linuxlinux_kernel
2.6.22.16
linuxlinux_kernel
2.6.22.17
linuxlinux_kernel
2.6.22.18
linuxlinux_kernel
2.6.22.19
linuxlinux_kernel
2.6.22.20
linuxlinux_kernel
2.6.22.21
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
hardy
Fixed 2.6.24-19.36
released
gutsy
dne
feisty
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
dapper
not-affected
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
not-affected
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
Fixed 2.6.22-15.56
released
feisty
dne
dapper
dne
Common Weakness Enumeration
References