CVE-2008-3275
12.08.2008, 23:41
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.25.15 |
debian | debian_linux | 4.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||
linux-source-2.6.15 |
| ||||||||
linux-source-2.6.20 |
| ||||||||
linux-source-2.6.22 |
|
References