CVE-2008-2365

Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514.  NOTE: this issue might only affect kernel versions before 2.6.16.x.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:N/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
linuxlinux_kernel
2.6.9
linuxlinux_kernel
2.6.10
linuxlinux_kernel
2.6.10:rc2
linuxlinux_kernel
2.6.11
linuxlinux_kernel
2.6.11:rc2
linuxlinux_kernel
2.6.11:rc3
linuxlinux_kernel
2.6.11:rc4
linuxlinux_kernel
2.6.11.4
linuxlinux_kernel
2.6.11.5
linuxlinux_kernel
2.6.11.6
linuxlinux_kernel
2.6.11.7
linuxlinux_kernel
2.6.11.8
linuxlinux_kernel
2.6.11.11
linuxlinux_kernel
2.6.11.12
linuxlinux_kernel
2.6.12
linuxlinux_kernel
2.6.12:rc1
linuxlinux_kernel
2.6.12:rc4
linuxlinux_kernel
2.6.12:rc5
linuxlinux_kernel
2.6.12.1
linuxlinux_kernel
2.6.12.2
linuxlinux_kernel
2.6.12.3
linuxlinux_kernel
2.6.12.4
linuxlinux_kernel
2.6.12.5
linuxlinux_kernel
2.6.12.6
linuxlinux_kernel
2.6.12.12
linuxlinux_kernel
2.6.12.22
linuxlinux_kernel
2.6.13
linuxlinux_kernel
2.6.13:rc1
linuxlinux_kernel
2.6.13:rc4
linuxlinux_kernel
2.6.13:rc6
linuxlinux_kernel
2.6.13:rc7
linuxlinux_kernel
2.6.13.1
linuxlinux_kernel
2.6.13.2
linuxlinux_kernel
2.6.13.3
linuxlinux_kernel
2.6.13.4
linuxlinux_kernel
2.6.14
linuxlinux_kernel
2.6.14:rc1
linuxlinux_kernel
2.6.14:rc2
linuxlinux_kernel
2.6.14:rc3
linuxlinux_kernel
2.6.14:rc4
linuxlinux_kernel
2.6.14.1
linuxlinux_kernel
2.6.14.2
linuxlinux_kernel
2.6.14.3
linuxlinux_kernel
2.6.14.4
linuxlinux_kernel
2.6.14.5
linuxlinux_kernel
2.6.15
linuxlinux_kernel
2.6.15:rc1
linuxlinux_kernel
2.6.15:rc2
linuxlinux_kernel
2.6.15:rc3
linuxlinux_kernel
2.6.15.1
linuxlinux_kernel
2.6.15.2
linuxlinux_kernel
2.6.15.3
linuxlinux_kernel
2.6.15.4
linuxlinux_kernel
2.6.15.11
linuxlinux_kernel
2.6.16
linuxlinux_kernel
2.6.16:rc1
linuxlinux_kernel
2.6.16.1
linuxlinux_kernel
2.6.16.7
linuxlinux_kernel
2.6.16.9
linuxlinux_kernel
2.6.16.11
linuxlinux_kernel
2.6.16.12
linuxlinux_kernel
2.6.16.13
linuxlinux_kernel
2.6.16.19
linuxlinux_kernel
2.6.16.23
linuxlinux_kernel
2.6.16.27
linuxlinux_kernel
2.6.17
linuxlinux_kernel
2.6.17:rc5
linuxlinux_kernel
2.6.17.1
linuxlinux_kernel
2.6.17.2
linuxlinux_kernel
2.6.17.3
linuxlinux_kernel
2.6.17.5
linuxlinux_kernel
2.6.17.6
linuxlinux_kernel
2.6.17.7
linuxlinux_kernel
2.6.17.8
linuxlinux_kernel
2.6.17.10
linuxlinux_kernel
2.6.17.11
linuxlinux_kernel
2.6.17.12
linuxlinux_kernel
2.6.17.13
linuxlinux_kernel
2.6.17.14
linuxlinux_kernel
2.6.18
linuxlinux_kernel
2.6.18.1
linuxlinux_kernel
2.6.18.3
linuxlinux_kernel
2.6.18.4
linuxlinux_kernel
2.6.19
linuxlinux_kernel
2.6.19:rc1
linuxlinux_kernel
2.6.19:rc2
linuxlinux_kernel
2.6.19:rc3
linuxlinux_kernel
2.6.19:rc4
linuxlinux_kernel
2.6.19.1
linuxlinux_kernel
2.6.19.2
linuxlinux_kernel
2.6.20
linuxlinux_kernel
2.6.20.1
linuxlinux_kernel
2.6.20.2
linuxlinux_kernel
2.6.20.3
linuxlinux_kernel
2.6.20.4
linuxlinux_kernel
2.6.20.5
linuxlinux_kernel
2.6.20.8
linuxlinux_kernel
2.6.20.9
linuxlinux_kernel
2.6.20.11
linuxlinux_kernel
2.6.20.13
linuxlinux_kernel
2.6.20.15
linuxlinux_kernel
2.6.21
linuxlinux_kernel
2.6.21:rc3
linuxlinux_kernel
2.6.21:rc4
linuxlinux_kernel
2.6.21:rc5
linuxlinux_kernel
2.6.21:rc6
linuxlinux_kernel
2.6.21.1
linuxlinux_kernel
2.6.21.2
linuxlinux_kernel
2.6.21.4
linuxlinux_kernel
2.6.21.6
linuxlinux_kernel
2.6.21.7
linuxlinux_kernel
2.6.22
linuxlinux_kernel
2.6.22.1
linuxlinux_kernel
2.6.22.3
linuxlinux_kernel
2.6.22.4
linuxlinux_kernel
2.6.22.5
linuxlinux_kernel
2.6.22.6
linuxlinux_kernel
2.6.22.7
linuxlinux_kernel
2.6.22.8
linuxlinux_kernel
2.6.22.11
linuxlinux_kernel
2.6.22.12
linuxlinux_kernel
2.6.22.13
linuxlinux_kernel
2.6.22.14
linuxlinux_kernel
2.6.22.15
linuxlinux_kernel
2.6.22.16
linuxlinux_kernel
2.6.22.17
linuxlinux_kernel
2.6.23
linuxlinux_kernel
2.6.23:rc1
linuxlinux_kernel
2.6.23.1
linuxlinux_kernel
2.6.23.2
linuxlinux_kernel
2.6.23.3
linuxlinux_kernel
2.6.23.4
linuxlinux_kernel
2.6.23.5
linuxlinux_kernel
2.6.23.6
linuxlinux_kernel
2.6.23.7
linuxlinux_kernel
2.6.23.9
linuxlinux_kernel
2.6.23.10
linuxlinux_kernel
2.6.23.14
linuxlinux_kernel
2.6.23_rc1:_rc1
linuxlinux_kernel
2.6.24
linuxlinux_kernel
2.6.24:rc2
linuxlinux_kernel
2.6.24:rc3
linuxlinux_kernel
2.6.24.1
linuxlinux_kernel
2.6.24.2
linuxlinux_kernel
2.6.24.6
linuxlinux_kernel
2.6.24_rc4:_rc4
linuxlinux_kernel
2.6.24_rc5:_rc5
linuxlinux_kernel
2.6.25
linuxlinux_kernel
2.6.25.1
linuxlinux_kernel
2.6.25.2
linuxlinux_kernel
2.6.25.3
linuxlinux_kernel
2.6.25.4
linuxlinux_kernel
2.6.25.5
redhatenterprise_linux
4.0
redhatenterprise_linux
4.0
redhatenterprise_linux
4.0
redhatenterprise_linux_desktop
4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
hardy
not-affected
gutsy
dne
feisty
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
dapper
Fixed 2.6.15-52.69
released
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
not-affected
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
not-affected
feisty
dne
dapper
dne
References