CVE-2008-2729

arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.19
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
hardy
not-affected
gutsy
dne
feisty
dne
edgy
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
edgy
dne
dapper
Fixed 2.6.15-52.69
released
linux-source-2.6.17
hardy
dne
gutsy
dne
feisty
dne
edgy
not-affected
dapper
dne
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
not-affected
edgy
dne
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
not-affected
feisty
dne
edgy
dne
dapper
dne
References